Senior Application Security Engineer
Core
Senior engineer owning the full lifecycle of bug bounty reports, from intake and reproduction to severity assessment, root cause analysis, and fix verification within a Product Security Incident Response Team.
Role type
Senior IC application security engineer (bug bounty & vulnerability research)
Builds
Verified fixes for web and application vulnerabilities, security research findings, and incident response outcomes
Domain
SaaS platform security, web application security, vulnerability research
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vulnerability reproduction, root cause analysis, severity assessment, code review, remediation design, coordinated vulnerability disclosure, technical mentorship, written communication
Preferred skills
variant hunting, original platform security research, forensic postmortems, handling severity disputes
Technologies
Java, JavaScript, Python, Git, Gradle, Maven, CI/CD pipelines, Claude Code
Responsibilities
Triage and resolve bug bounty reports end-to-end; reproduce and validate vulnerabilities; perform code review and root cause analysis; propose and verify remediations; mentor earlier-career engineers; conduct variant hunts and original security research; lead major product security incidents and forensic postmortems
Seniority
Senior, hands-on IC with mentorship responsibilities