Bug Bounty Analyst
Leicester, England, United Kingdom · Full Time
Be the first to apply
- Experience
- 2+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join Global Payments Inc. in Leicester as a Bug Bounty Analyst within our Security Operations team. This role offers the chance to work in a dynamic, fast-paced sector, playing a crucial part in the daily management of our Bug Bounty Program aimed at enhancing global commerce security.
Key Responsibilities
- Evaluate and support assigning severity levels to reported vulnerabilities using the Common Vulnerability Scoring System (CVSS).
- Communicate findings effectively to both technical and non-technical stakeholders.
- Formulate strategies for mitigating identified vulnerabilities, including setting timelines and plans.
- Coordinate remediation efforts of issues identified through Bug Bounty and Vulnerability Disclosure Programs, engaging directly with ethical hackers.
- Analyze missed vulnerabilities to improve scanner visibility and address security gaps.
- Identify absent security controls that could prevent future incidents and ensure their implementation.
- Expand the program by onboarding new assets and collaborating with Risk Management to document risks based on bug bounty findings.
- Maintain knowledge of data security standards and regulations such as PCI, HIPAA, GDPR, PII protection, and NIST Cyber Security Framework.
- Work with Legal and Privacy teams when dealing with critical data exposure from findings.
- Follow established runbooks for daily tasks.
Requirements
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent relevant experience.
- At least 2 years of relevant experience in vulnerability management or bug bounty program management.
- Familiarity with network operations, system administration (Unix, Linux, MAC, Windows), security operations, intrusion detection, SIEM tools, penetration testing, web application assessments, secure coding, and cloud technologies.
Preferred Qualifications
- Certifications such as CompTIA Security+, CompTIA PenTest, SSCP, CISM, CISA, CEH, CCSLP, GIAC GWEB, eJPT, or OSCP.
- Experience with security compliance like PCI, GDPR, and NIST frameworks.
- Experience using ticketing tools like ServiceNow or JIRA.
Desired Skills and Attributes
- Excellent verbal and written communication abilities.
- Strong attention to detail and active listening skills.
- Capability to communicate effectively and persuade others towards goal achievement.
- Adept at facilitating discussions and driving resolutions.
- Solid vulnerability management knowledge, with understanding of exploitation techniques.
- Ability to work independently with general guidance and handle issues within defined frameworks.
- Commitment to ongoing learning about emerging threats and security measures.
About the Team
Work with a diverse, global team that values collaboration and innovation. At Global Payments Inc., you’ll find career growth opportunities beyond borders and a culture that encourages ownership, curiosity, and team success.
Equal Opportunity
Global Payments Inc. is proud to be an equal opportunity employer.
Minimum education
Bachelor's Degree