Security Analyst responsible for triaging, reproducing, and resolving vulnerability reports from Stripe's bug bounty program. Requires strong web security knowledge, offensive security skills, and ability to communicate with researchers and internal teams.
Salary not listed
RemoteSecurity Engineering
About the role
Responsibilities
Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program
Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers
Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies
Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders
Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation
Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives
Provide tactical support for vulnerability management triage processes to augment the team as needed
Prepare and implement improvements to the overall bug bounty program
Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation
Minimum Requirements
Proven ability to follow bug reports and accurately triage security vulnerabilities
Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
Competent in offensive security tools (e.g., Burp Suite, custom scripting)
Ability to think like an attacker to understand the impact of vulnerabilities
Proficient in clear communication, conveying technical concepts to various stakeholders
Experience in one of the following areas: bug bounty program or triaging security vulnerability reports; knowledge of Stripe products and general security expertise
Preferred Qualifications
Experience in technical support, operations, or similar roles with technical systems exposure
Prior participation in or experience with bug bounty programs
Experience analyzing source code for security vulnerabilities
Proficiency in scripting languages (e.g., Python, Ruby) for automation
Familiarity with cloud-based services (e.g., AWS, GCP)
Certifications such as OSWA or BSCP
Skills
bug bountyvulnerability triageweb securityowasp top 10cweburp suiteoffensive securityPythonRubyAWSGCPsource code analysis
Security Engineer securing frontier AI compute infrastructure. Own cloud/bare-metal control plane security, build guardrails as code, engineer detection/response, and secure multi-tenant boundaries for high-value training workloads.
218k – 252k/yr
On-site5+ YOESecurity Engineering
Security Engineer, Corp IT
FluidstackAustin, TX +3
Secure Fluidstack's corporate environment end-to-end including identity, endpoints, SaaS, email, and zero-trust access for a rapidly growing workforce. Build detections, automate controls as code, and respond to incidents protecting frontier AI infrastructure.
218k – 252k/yr
On-site5+ YOESecurity Engineering
Product Security Engineer
Collective Intelligence ProjectSan Francisco, CA
Build and operate an agentic application security program using AI for automated testing, triage, and PR review. Drive end-to-end vulnerability remediation, eliminate vulnerability classes via code changes, and lead threat modeling for a fintech platform handling sensitive financial data. Requires 4+ years appsec experience, hands-on tooling expertise, enthusiasm for LLMs, and Python engineering skills.
170k – 200k/yr
Hybrid4+ YOESecurity Engineering
Information Security Engineer, Bare Metal
FluidstackNew York, NY +3
Build and own end-to-end security for Fluidstack's bare metal AI compute fleet, from supply chain to decommissioning. Harden Linux, enforce BMC security, implement zero-trust networking and encryption at gigawatt scale.
168k – 225k/yr
On-site5+ YOESecurity Engineering
Cloud Security Engineer
PolymarketNew York, NY
Own and improve Polymarket's AWS security posture by designing and enforcing security controls in infrastructure code, managing cloud telemetry and detection, and driving compliance. Requires 4+ years cloud security experience, deep AWS expertise, and IaC skills.