Bug Bounty Analyst
London, England, United Kingdom · Full Time
Be the first to apply
- Experience
- 2+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 6 ദിവസം മുൻപ്
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science, Info Security, or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Opportunity
Join a leading global payments company as a Bug Bounty Analyst within the Security Operations team. In this dynamic role, you will support the management and continual improvement of the Bug Bounty Program, playing an essential role in maintaining and enhancing the security posture of the organization.
Core Responsibilities
- Evaluate and prioritize vulnerabilities disclosed in the Bug Bounty Program based on the Common Vulnerability Scoring System (CVSS).
- Communicate technical vulnerability details effectively to stakeholders, catering to both technical and non-technical audiences.
- Formulate mitigation strategies and develop timelines to address identified security issues.
- Coordinate remediation efforts by liaising between whitehat researchers and internal teams.
- Analyze vulnerability findings to detect gaps in existing scanner coverage and collaborate on closing these visibility gaps.
- Identify and track missing security controls necessary to mitigate reported vulnerabilities until resolution.
- Expand the Bug Bounty Program by onboarding additional assets to improve coverage.
- Collaborate with Risk Management to document risks and issues surfaced through the program.
- Maintain up-to-date knowledge on relevant data security standards and regulations including PCI, HIPAA, GDPR, PII protection, and the NIST Cybersecurity Framework.
- Coordinate with Legal and Privacy departments when critical data exposure is identified due to vulnerabilities.
- Follow established operational runbooks for routine activities to ensure consistency.
Qualifications and Experience
- Bachelor's degree in Computer Science, Information Security, or a closely related discipline or equivalent professional experience.
- Minimum two years of experience in vulnerability management or direct involvement with Bug Bounty Program operations.
- Familiarity with network operations, system administration (Unix, Linux, Windows), security incident event management, intrusion detection systems, penetration testing, secure coding, and cloud technologies.
Preferred Credentials
- Professional certifications such as CompTIA Security+, CompTIA PenTest+, SSCP, CISM, CISA, CEH.
- Additional certifications including CCSLP, GIAC Web Application Defender (GWEB), eJPT, or OSCP.
- Expertise with compliance frameworks like PCI DSS, GDPR, and NIST Cyber Security Framework.
- Experience handling ticketing systems, particularly ServiceNow or JIRA.
Desired Skills and Attributes
- Excellent verbal and written communication capabilities.
- Strong attention to detail with active listening skills.
- Proven effectiveness in persuading and driving complex goals.
- Facilitation skills to lead meetings toward productive resolutions.
- In-depth understanding of vulnerability assessment and exploit methodologies.
- Ability to independently manage moderately complex issues using sound judgment.
- Proactive learning and adaptation to evolving security threats and mitigations.
About the Team
Work with a diverse and inclusive global team recognized for industry expertise, collaborative spirit, and innovative mindset. This role offers a unique opportunity for professional development and cross-border collaboration in a fast-paced environment.
Equal Opportunity
Global Payments Inc. is committed to being an equal opportunity employer fostering diversity and inclusion.
Minimum education
Bachelor's Degree