Senior Application Security Engineer
Own application security bug bounty reports from intake through verified remediation. Lead vulnerability research, complex triage, product security incidents, forensic postmortems, and mentorship within PSIRT.
Responsabilidades
- Own bug bounty reports through intake, reproduction, severity scoring, root-cause analysis, remediation, fix verification, and closure.
- Reproduce vulnerabilities and complete proof-of-concept code when required.
- Escalate and resolve complex, high-severity reports, including multi-step exploit chains and cross-system issues.
- Review code, identify underlying defects, propose or co-design remediations, and verify fixes.
- Communicate with bug bounty researchers, handle validity and severity disputes, and report risk and status to stakeholders.
- Mentor PSIRT engineers and improve triage standards and program practices.
- Conduct variant hunts and original platform security research.
- Lead major product security incidents and coordinate response across teams.
- Run forensic postmortems to identify how issues reached production and confirm remediation effectiveness.
Requisitos
- 8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research.
- Expertise in web and application vulnerabilities, exploitation techniques, vulnerability reproduction, severity assessment, and coordinated disclosure.
- Strong code comprehension in Java, JavaScript, and Python, including root-cause analysis in large codebases and pull-request review.
- Ability to write code, propose concrete fixes, and collaborate with engineering on remediation.
- Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC practices.
- Proficiency with Claude Code or an equivalent AI coding assistant.
- Exceptional written communication for working with external researchers, engineering teams, and leadership.