Senior Security Engineer
Company: Tbwa Chiat/Day Inc
Location: San Francisco
Posted on: April 5, 2025
Job Description:
We are Bugcrowd. Since 2012, we've been empowering organizations
to take back control and stay ahead of threat actors by uniting the
collective ingenuity and expertise of our customers and trusted
alliance of elite hackers, with our patented data and AI-powered
Security Knowledge Platform. Our network of hackers brings diverse
expertise to uncover hidden weaknesses, adapting swiftly to
evolving threats, even against zero-day exploits. With unmatched
scalability and adaptability, our data and AI-driven CrowdMatch
technology in our platform finds the perfect talent for your unique
fight. We aim to create a new era of modern crowdsourced security
that outpaces threat actors. Unleash the ingenuity of the hacker
community with Bugcrowd, visit www.bugcrowd.com. Based in San
Francisco and New Hampshire, Bugcrowd is supported by General
Catalyst, Rally Ventures, Costanoa Ventures, and others.Job
SummaryThe Senior Security Engineer's role is to aid the
organizational security efforts of Bugcrowd, while proactively
improving our security posture. As the last line of defense for one
of the largest crowdsourced security platforms, you will be
challenged regularly! Accordingly, we require a motivated team who
are willing to push their own boundaries and step out of their
comfort zones, while being supported by Bugcrowd and the director
of Cybersecurity. The Senior Security Engineer will receive
mentoring from the team, while providing mentoring to others, and
you will be responsible for managing your individual engineering
workload. This role also requires excellent communication skills as
the cybersecurity department liaises with all other departments
within the company.Essential Duties and Responsibilities
- Security Architecture and Application Security - Working with
developers to uplift the current security controls and architecting
solutions.
- Tool Creation - Creating tools used internally for securing the
company, majorly in Python and Golang.
- Operations / Incident Response - Aiding with the process of
Incident Response, and security operational activities when
required.
- Risk Management - Assessing the risk behind security issues,
and tracking core metrics.
- Pentesting - Performing security assessments of Bugcrowd assets
(and vendors).
- Quality Improvement - Contributing to the continual improvement
of the Cybersecurity team's policies and standards of
practice.Experience Required
- 5+ years of experience in a similar role or its
equivalent.
- Familiarity with application security testing techniques (can
perform a security assessment and code review should they be given
a product, identifying weaknesses, ability to document findings,
exploit development experience is a bonus).
- Knowledge of OWASP Top 10 and common security vulnerabilities
of modern web apps.
- Knowledge of Incident Response and operating systems as this
role requires responding to incidents within the specified
timezone.
- Knowledge of threat intelligence.
- Ability to understand a vulnerability and work with developers
to patch it.
- Great communicator who is comfortable communicating across
multiple teams.
- Self-motivated, autonomous and organized - must be able to
operate from a calendar, be punctual, and manage timelines of
projects/tasks for self and others.
- Cloud experience (AWS preferred).
- Understanding of Identity and Access Management (IAM).
- Ability to proactively find solutions (i.e., figure things out
for themselves, look at configurations, learn what they mean,
document potential solutions to solve the problems).
- Has the ability to be self-sufficient.
- Has some prior red teaming knowledge.
- Familiarity with git and pull requests is a must.
- Familiarity with a ticketing system / issue tracking system is
a must (e.g: Notion and Jira).
- Preferred Bachelor's Degree in Computer Science, MIS or
equivalent experience.Working Conditions
- The ideal candidate must be able to complete all physical
requirements of the job with or without reasonable
accommodation.
- Sitting and/or standing - Must be able to remain in a
stationary position 50% of the time.
- Carrying and/or lifting - Must be able to carry/move laptop as
needed throughout the work day.
- Environment - remote, work-from-home 100% of the time.Culture
- At Bugcrowd, we understand that diversity in the workplace is
vital to a company's success and growth. We strive to make sure
that people are included and have a sense of being part of making
Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that
Bugcrowd feels like a family, and we strive to maintain that
internally as well.
- Our team consists of a broad range of people: musicians,
adventure sports junkies, nature lovers, parents, cereal
enthusiasts, night owls, cyclists, artists-you get the point.At
Bugcrowd, we are solving security threats and vulnerabilities that
are relevant to everyone, therefore we believe solving these
problems takes all kinds of backgrounds. We value the perspectives
and experiences people from underrepresented backgrounds
bring.DisclaimerThis position has access to highly confidential,
sensitive information relating to the technologies of Bugcrowd. It
is essential that the applicant possess the requisite integrity to
maintain the information in the strictest confidence.The company is
authorized to obtain background checks for employment purposes
under state and federal law. Background checks will be conducted
for positions that involve access to confidential or proprietary
information (including trade secrets).Background checks may include
Social Security verification, prior employment verification,
personal and professional references, educational verification, and
criminal history. Applicants with conviction histories will not be
excluded from consideration to the extent required by law.Bugcrowd
is EOE, Disability/Age Employer.Individuals seeking employment at
Bugcrowd are considered without regards to race, color, religion,
national origin, age, sex, marital status, ancestry, physical or
mental disability, veteran status, gender identity, or sexual
orientation.
#J-18808-Ljbffr
Keywords: Tbwa Chiat/Day Inc, San Francisco , Senior Security Engineer, Engineering , San Francisco, California
Didn't find what you're looking for? Search again!
Loading more jobs...