Security Analyst, Bug Bounty
Stripe
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Join Stripe’s Vulnerability Management team as a Security Analyst (Bug Bounty). You’ll be on the front lines of bug bounty triage and researcher engagement, owning the end-to-end lifecycle of vulnerability reports and helping continuously improve the program.
Responsibilities
- Analyze, assess, reproduce, and triage incoming bug bounty security vulnerability reports
- Communicate with security researchers to clarify unclear reports and drive engagement with top hackers
- Investigate root causes of vulnerabilities and advise mitigation strategies to product and engineering teams
- Drive submissions to resolution, coordinating with product and engineering stakeholders
- Act as a security bridge between external researchers and internal teams to enable rapid remediation
- Perform in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks
- Provide tactical support to augment vulnerability management triage processes as needed
- Prepare and implement improvements to the bug bounty program (e.g., researcher campaigns, scoring transparency)
- Provide feedback and requirements for tool development, leveraging opportunities for automation
Requirements
- Proven ability to follow bug reports and accurately triage security vulnerabilities
- Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
- Competence with offensive security tools (e.g., Burp Suite, custom scripting)
- Ability to think like an attacker to understand vulnerability impact
- Proficient clear communication of technical concepts to varied stakeholders
- Experience in bug bounty programs or triaging security vulnerability reports
Preferred Qualifications
- Experience in technical support/operations with exposure to technical systems
- Prior participation/experience with bug bounty programs
- Experience analyzing source code for security vulnerabilities
- Scripting proficiency (e.g., Python, Ruby)
About Stripe
Stripe is a financial infrastructure platform that enables businesses to accept payments, grow revenue, and accelerate new business opportunities. The company serves millions of companies, from enterprises to startups, and focuses on improving the security and reliability of its payment ecosystem. Stripe is hiring for its Vulnerability Management team within its security organization.
Scraped 7/23/2026