R

Bug Bounty Triage Analyst

Rooted

Singapore · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
2 weeks ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About The Role

You will manage the queue of security vulnerability reports submitted by external researchers. Your responsibilities include reproducing each reported issue, assessing its severity based on tangible impact evidence, and rewriting the report so that engineering teams can proceed without further clarification. Additionally, you serve as the key contact for researchers, communicating clearly when a report is a duplicate, out of scope, or not a valid vulnerability.

Key Responsibilities

  • Verify and reproduce reported vulnerabilities and confirm severity with proof.
  • Reformat and clarify findings to enable engineers to take immediate action without extra queries.
  • Maintain clear communication with security researchers, including explaining decisions when reports are invalid or declined.

Required Qualifications

  • Solid understanding of web security principles and fundamentals.
  • Ability to quickly and fairly assess severity levels for reported vulnerabilities.
  • Excellent written communication skills suitable for de-escalating conflicts.

Preferred Skills

  • Experience participating as a security researcher in bug bounty programs.
  • Familiarity with CVSS (Common Vulnerability Scoring System) standards.

How they work

Communication Attention to Detail
🤖
Online · instant AI help
Broxer