Bug Bounty Security Researcher

Posted 3ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Bug Bounty Security Researcher identifying and reporting vulnerabilities in software applications and systems for Inspectiv. Contributing to improving security and participating in bug bounty programs.

Responsibilities:

  • Conduct thorough research on target systems, applications, and networks to identify potential vulnerabilities.
  • Develop and execute custom attack vectors using various tools and techniques (e.g., fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side-Request-Forgery (SSRF), Remote Code Execution).
  • Identify and exploit vulnerabilities in a responsible manner, ensuring that no harm is caused to the system or data being tested.
  • Document all findings, including detailed descriptions of discovered vulnerabilities, proof-of-concept code, and steps taken to reproduce the issue.
  • Participate in regular bug bounty programs and contribute to the improvement of our products and services.

Requirements:

  • 1 year of experience in security research, penetration testing, or vulnerability assessment.
  • Strong understanding of computer systems, networks, and software applications.
  • Some proficiency with programming languages (e.g., Python, C++, JavaScript, HTML) and offensive security tools (e.g., Burp Suite, OWASP ZAP, Nmap, Kali Linux).
  • Experience with bug bounty programs and responsible disclosure practices.
  • Excellent analytical and problem-solving skills.
  • Strong communication and documentation skills.
  • Relevant Application Security Certifications: BurpSuite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), Offensive Security Certified Professional (OSCP).
  • 3+ years of experience in security research, penetration testing, or vulnerability assessment.
  • Has an awarded and recognized public Bug Bounty profile.
  • Has recognized contributions to Common Vulnerabilities and Exposures (CVEs)

Benefits:

  • Bounty awards for accepted vulnerabilities
  • Recognition for submitted reports on various leaderboards on and off platform
  • Experience in performing real-world penetration testing in Web Application, Mobile and Network Security
  • A collaborative and empathy-led culture that takes security seriously and is on a mission to Secure The Internet
  • A chance to participate in private, exclusive bug bounty programs