Back to Jobs
Bugcrowd
Development 1h ago

Application Security Engineer (ASE)

Bugcrowd
BrazilBrazil
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

Backend42mFree Trial ✨
Start 10-Day Free Trial
DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
Automation EngineerCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

How would you rate this job post?

See what other professionals think about this role.

banner

Bugcrowd is a pioneer in the field of crowdsourced cybersecurity, offering a revolutionary approach to vulnerability discovery and bug bounty programs. By leveraging a global community of skilled security researchers, Bugcrowd empowers organizations to identify and remediate potential security threats more efficiently and effectively. The company's innovative platform provides a robust infrastructure for managing bug bounty programs, vulnerability disclosure, and penetration testing, allowing businesses to stay ahead of emerging security risks. With a strong focus on security, transparency, and community engagement, Bugcrowd has established itself as a trusted partner for organizations seeking to strengthen their cybersecurity posture. By providing a comprehensive suite of cybersecurity solutions, Bugcrowd helps companies to protect their assets, data, and customers from increasingly sophisticated cyber threats. As a leader in the cybersecurity industry, Bugcrowd continues to push the boundaries of innovation, collaborating with its community of researchers and customers to develop cutting-edge security solutions. With its unique approach to crowdsourced security, Bugcrowd is dedicated to making the digital world a safer and more secure place. The company's commitment to security, quality, and community has earned it a reputation as a pioneer in the field, and its contributions to the cybersecurity landscape are expected to have a lasting impact. Bugcrowd's success can be attributed to its ability to bring together a diverse group of security researchers, providing them with the tools and resources needed to identify vulnerabilities and develop innovative solutions. This collaborative approach has enabled Bugcrowd to build a comprehensive database of security vulnerabilities, which is used to inform and improve the company's security solutions. As the cybersecurity landscape continues to evolve, Bugcrowd is well-positioned to remain at the forefront of innovation, providing organizations with the security solutions they need to stay ahead of emerging threats. With its strong community of security researchers, cutting-edge technology, and commitment to security, Bugcrowd is an invaluable resource for businesses seeking to protect themselves from cyber threats.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Application Security Engineer (ASE) at Bugcrowd | HireSkys