Senior Application Security Engineer
Core
Senior engineer owning the full lifecycle of bug bounty reports, from intake and reproduction to severity assessment, root cause analysis, and fix verification within a Product Security Incident Response Team.
Role type
Senior IC application security engineer (bug bounty & vulnerability research)
Builds
Verified fixes for web and application vulnerabilities, security research findings, and incident response outcomes
Domain
Cybersecurity, Application Security, Bug Bounty Programs
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability reproduction and validation, Root cause analysis in code, Severity scoring and risk assessment, Coordinated vulnerability disclosure, Code review and remediation design, Technical mentorship, Written communication for stakeholder management, Variant hunting, Forensic postmortems
Preferred skills
Expertise in Java, JavaScript, and Python, Proficiency with AI coding assistants (e.g., Claude Code), Experience with Git, Gradle, Maven, and CI/CD pipelines
Technologies
Java, JavaScript, Python, Git, Gradle, Maven, CI/CD pipelines, Claude Code
Responsibilities
Triage and resolve bug bounty reports end-to-end, Reproduce and validate vulnerabilities with proof-of-concept code, Conduct variant hunts and original platform security research, Lead major product security incidents and forensic postmortems, Mentor earlier-career engineers on triage standards, Communicate technical findings to researchers and internal stakeholders
Seniority
Senior, hands-on IC with mentorship responsibilities