Stripe

Stripe

Security Analyst, Bug Bounty

Remote (Worldwide)RemotePosted Today
Full TimeRemote

See how this job matches your profile

Sign in for an AI-powered fit score, breakdown, and a tailored resume.

Sign in

Job Description

Who we areAbout StripeStripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payme

Key Highlights

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program
  • Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers
  • Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies
  • Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders
  • Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation

Qualifications

Required Qualifications

  • Proven ability to follow bug reports and accurately triage security vulnerabilities
  • Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
  • Competent in offensive security tools (e.g., Burp Suite, custom scripting)
  • Ability to think like an attacker to understand the impact of vulnerabilities
  • Proficient in clear communication, conveying technical concepts to various stakeholders
  • Experience in one of the following areas Bug bounty program or triaging security vulnerability reportsKnowledge of Stripe products and general security expertise
  • Bug bounty program or triaging security vulnerability reports
  • Knowledge of Stripe products and general security expertise
  • Experience in technical support, operations, or similar roles with technical systems exposure
  • Prior participation in or experience with bug bounty programs
  • Experience analyzing source code for security vulnerabilities
  • Proficiency in scripting languages (e.g., Python, Ruby) for automation
  • Familiarity with cloud-based services (e.g., AWS, GCP)
  • Certifications such as OSWA or BSCP

Skills & Technologies

PythonRubyAWSGCP

Interested in this role?

Sign in or create a free account to see how this job matches your skills, apply with one click, and let our AI tailor your resume.

Sign in to apply
AI-powered resume optimization
Save and track your applications

Job Details

Employment Type

Full Time

Location

Remote (Worldwide)

Work Mode

Remote

Posted

Today