hero

Rally Ventures unites an intersecting portfolio of companies at the frontier of business technology.

Discover job opportunities across our portfolio.

Principal Security Engineer

Bugcrowd

Bugcrowd

Australia
Posted 6+ months ago

Company Summary
Bugcrowd is the world’s #1 crowdsourced security company. Our award-winning platform combines actionable, contextual intelligence with the skill and experience of the world’s most elite hackers to help leading organizations solve security challenges, protect customers, and make the digitally connected world a safer place.

Job Summary
The Senior DevSecOps Security Engineer’s role is to aid the security efforts of Bugcrowd, while proactively making changes to further improve our security posture. To achieve this goal, we require a motivated team who are willing to push their own boundaries and step out of their comfort zones. You will be challenged on a regular basis, especially because you are the last line of defense for one of the largest crowdsourced security platforms! The Senior Security Engineer will receive mentoring from the team, while providing mentoring to others. The role requires excellent communication skills as the cybersecurity department liaises with all other departments within the company.


Essential Duties and Responsibilities
Security Architecture and Application Security - Working with developers to uplift the current security controls and architecting solutions
Tool Creation - Create tools used internally for securing the company, majorly in Python and Golang
Operations / Incident Response - Aid with the process of Incident Response, security operational activities when required
Risk Management - Assess the risk behind security issues, track core metrics
Pentesting - Performing security assessments of Bugcrowd assets (and vendors)
Operations / Incident Response - Aid with the process of Incident Response, security operational activities when required
Tool Creation - Create tools used internally for securing the company, majorly in Python and Golang

Supervisory Responsibility
Mentor other individuals within the team

Education

Preferred Bachelors
Degree in Computer Science, MIS or equivalent experience

Experience

Minimum Years of Experience
Description

5+ experience in a similar role or its equivalent.

Knowledge, Skills, and Abilities


Familiarity with application security testing techniques (can perform a security assessment and code review should they be given a product, identifying weaknesses, exploit development experience is a bonus)
Knowledge of OWASP Top 10 and common security vulnerabilities of modern web apps
Knowledge of Incident Response and operating systems as this role requires responding to incidents within the specified timezone
Knowledge of threat intelligence
Ability to understand a vulnerability and work with developers to patch it
Knowledge and proficiency with coding in at least two of: Python, JavaScript, Ruby, Golang
Great communicator who is comfortable communicating across multiple teams
Self motivated, autonomous and organised - must be able to operate from a calendar,be punctual, and being able to manage timelines of projects/tasks for self and others
Cloud experience (AWS preferred)
Understanding of Identity and Access Management (IAM)
Ability to figure things out themselves (look at configurations, learn what they mean, and solve problems)
Has the ability to be self-sufficient
Has some prior red teaming knowledge
Familiarity with git and pull requests is a must
Familiarity with a ticketing system / issue tracking system is a must (e.g: Jira)

Working Conditions and Physical Requirements

Culture
At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring. We are a supportive & collaborative team who understand that reaching Bugcrowd’s potential depends on the happiness of the employee.


Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.


Apply at: https://www.bugcrowd.com/about/careers/