Staff Security Engineer - Application/Product Security
Core
Technical core of the bug bounty program within the Product Security Incident Response Team (PSIRT), owning reports from intake through resolution, reproducing vulnerabilities, assessing severity, and verifying fixes.
Role type
Staff Application Security Engineer (Bug Bounty & PSIRT)
Builds
Verified fixes for web and application vulnerabilities, security research findings, and incident response outcomes.
Domain
Application Security / Bug Bounty / Product Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability reproduction and validation, root cause analysis, severity assessment, code review, remediation design, technical communication, mentorship, variant hunting, forensic postmortems
Preferred skills
None stated
Technologies
Java, JavaScript, Python, Git, Gradle, Maven, CI/CD pipelines, Claude Code
Responsibilities
Triage and resolve bug bounty reports end-to-end, act as primary technical contact for researchers, mentor earlier-career engineers, conduct variant hunts and original security research, lead major product security incidents, run forensic postmortems
Seniority
Staff, hands-on IC with mentorship responsibilities