xelys jobs xelys jobs

Security Analyst, Bug Bounty

Stripe

full-remotemidpermanentsecurity Anywhere in the World 62 days ago via WWR

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Bug BountyVulnerability ManagementTriageOWASP Top 10CWEsWeb SecurityOffensive SecurityBurp SuiteScriptingRoot Cause Analysis

About the role

Role Overview

Join Stripe’s Vulnerability Management team as a Security Analyst (Bug Bounty). You’ll be on the front lines of bug bounty triage and researcher engagement, owning the end-to-end lifecycle of vulnerability reports and helping continuously improve the program.

Responsibilities

  • Analyze, assess, reproduce, and triage incoming bug bounty security vulnerability reports
  • Communicate with security researchers to clarify unclear reports and drive engagement with top hackers
  • Investigate root causes of vulnerabilities and advise mitigation strategies to product and engineering teams
  • Drive submissions to resolution, coordinating with product and engineering stakeholders
  • Act as a security bridge between external researchers and internal teams to enable rapid remediation
  • Perform in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks
  • Provide tactical support to augment vulnerability management triage processes as needed
  • Prepare and implement improvements to the bug bounty program (e.g., researcher campaigns, scoring transparency)
  • Provide feedback and requirements for tool development, leveraging opportunities for automation

Requirements

  • Proven ability to follow bug reports and accurately triage security vulnerabilities
  • Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
  • Competence with offensive security tools (e.g., Burp Suite, custom scripting)
  • Ability to think like an attacker to understand vulnerability impact
  • Proficient clear communication of technical concepts to varied stakeholders
  • Experience in bug bounty programs or triaging security vulnerability reports

Preferred Qualifications

  • Experience in technical support/operations with exposure to technical systems
  • Prior participation/experience with bug bounty programs
  • Experience analyzing source code for security vulnerabilities
  • Scripting proficiency (e.g., Python, Ruby)

About Stripe

Stripe is a financial infrastructure platform that enables businesses to accept payments, grow revenue, and accelerate new business opportunities. The company serves millions of companies, from enterprises to startups, and focuses on improving the security and reliability of its payment ecosystem. Stripe is hiring for its Vulnerability Management team within its security organization.

Scraped 7/23/2026