Security Analyst, Bug Bounty
Core
Triage and analyze security vulnerability reports from Stripe's bug bounty program, coordinate resolutions with engineering teams, and drive program effectiveness.
Role type
Security Analyst (Bug Bounty Triage)
Builds
Stripe's bug bounty program and security posture
Domain
Cybersecurity / Financial Infrastructure
Deliverable
client delivery
Required skills
Vulnerability triage, web security knowledge (OWASP Top 10, CWEs), offensive security tools (Burp Suite), attacker mindset, clear technical communication, product configuration understanding
Preferred skills
Scripting (Python, Ruby), cloud services (AWS, GCP), source code analysis, OSWA or BSCP certification
Technologies
Burp Suite, Python, Ruby, AWS, GCP
Responsibilities
Analyze, assess, reproduce, and triage incoming security vulnerability reports; Communicate with security researchers to clarify reports and drive engagement; Understand root causes of vulnerabilities to advise mitigation strategies; Drive submission lifecycle to resolution with engineering stakeholders; Conduct data analysis on bug reports to identify systemic risks; Provide feedback for tool development to enhance triage workflows
Seniority
Individual Contributor

