ย 

Product Security Analyst

RemoteMid-level
๐Ÿ’ฐ$100โ€“146K
๐Ÿ‡บ๐Ÿ‡ธ United States
๐Ÿ‡จ๐Ÿ‡ฆ Canada
๐Ÿ’ฐEquity
Technology

HackerOne is the global leader in human-powered security, harnessing the creativity of the worldโ€™s largest community of security researchers with cutting-edge AI to protect your digital assets. The HackerOne Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including bug bounty, pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.

Position Summary

HackerOne is seeking a dynamic individual with a passion for Information Security to join our Technical Services team. As a Security Analyst, you will gain hands-on technical experience and exposure to some of the worldโ€™s best hackers while delivering high-impact vulnerabilities to the top bug bounty programs in the industry.

This role requires excellent communication skills, intellectual curiosity and drive to acquire the technical skills youโ€™ll need to ensure every valid bug report is reproducible and provides value to HackerOne customers.

For AMER: This job reports to a Manager in-region and can be based anywhere within the United States or Canada.

What You Will Do

  • Evaluate assigned vulnerability reports submitted by hackers to determine the validity, risk and severity to HackerOne customers
  • Collaborate with hackers to address missing information from reports as well as educate the HackerOne community members when reports are invalid
  • Compose a technical summary for each valid report that includes clear and concise details regarding the impact, steps to reproduce and remediation advice
  • Ensure clear and efficient communication between hackers and customers
  • Proactively identify and solve issues, as well as accept and quickly respond to delegated work; as we are distributed, being able to win as a team to solve problems is critical to our success
  • Assess vulnerability findings and determine whether the submission is valid based on program policies, scope and impact.
  • Independently reproduce reported vulnerabilities in a test environment and compose a technical summary for valid findings.

Minimum Qualifications

  • Proven experience with vulnerability disclosure and bug bounty (experience managing a bug bounty program is a plus but not required)
  • Hands-on experience doing security testing or ethical hacking on web and mobile applications
  • Strong technical knowledge of OWASP top 10
  • Comfortable using security testing tools including Burpsuite
  • Excellent written and verbal communication skills
  • Experience using frameworks such as CVSS
  • Self-motivated and able to manage your time and energy output while maintaining a consistent and sustainable operational rhythm
  • English fluency
  • This role includes weekend work, with the schedule of working Friday-Tuesday during business day time hours. You will have Wednesdays/Thursdays off. Must be ok with working the weekend.
  • Must be based remotely in US or Canada. HackerOne is a digital-first company. This model offers our employees flexibility in time and location. All employees must be able to work and excel in a remote environment.

Preferred Qualifications

  • Experience managing a bug bounty program

Compensation Bands:
Tier Guide

Tier A

$116K โ€“ $146K โ€ข Offers Equity

Tier B

$105K โ€“ $130K โ€ข Offers Equity

Tier C

$100K โ€“ $124K โ€ข Offers Equity

Canada

CA$80K โ€“ CA$100K โ€ข Offers Equity

#LI-Remote

#LI-HM1

We are a Circle Back Initiative Employer and commit to responding to every applicant.

We're committed to building a global team! For certain roles outside the United States, U.K., and the Netherlands, we partner with Remote.com as our Employer of Record (EOR).

Employment at HackerOne is contingent on a background check.

HackerOne is an Equal Opportunity Employer in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, pregnancy, disability or veteran status, or any other protected characteristic as outlined by international, federal, state, or local laws.

This policy applies to all HackerOne employment practices, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. HackerOne makes hiring decisions based solely on qualifications, merit, and business needs at the time.

For US based roles only: Pursuant to the San Francisco Fair Chance Ordinance, all qualified applicants with arrest and conviction records will be considered for the position.

HackerOne Values

HackerOne commits to maintaining a strong, inclusive culture built for our employees and our community of hackers. We are driven by our five core values. We recognize that our mission is bigger than us, and therefore act with integrity at all times. As a team, we believe that transparency builds trust so we default to disclosure in our communications. Each individual executes with excellence, creating an environment of greater alignment and greater autonomy. We win as a team and respect all people to empower everyone to learn from each other, innovate, and grow.

ย 

HackerOne

HackerOne is the global leader in human-powered security, leveraging human ingenuity to pinpoint critical security flaws

โš–๏ธPeace and justice
Cybersecurity
Technology

LinkedIn

๐Ÿญcomputer and network security
๐ŸŽ‚2012

Other jobs at HackerOne

ย 

ย 

ย 

ย 

ย 

ย 

ย 

ย 

View all HackerOne jobs

Why OmniJobs?

  • Rare & hidden jobs
  • New jobs every day
  • No expired job posts
  • All jobs in English

Receive emails about similar jobs

Get alerts to your inbox about new open jobs that are similar to this one.

๐Ÿ‡บ๐Ÿ‡ธ United States
๐Ÿ‡จ๐Ÿ‡ฆ Canada
Technology
Remote

No spam. No ads. Unsubscribe anytime.

Similar jobs

ย 

ย 

ย 

ย 

ย 

ย 

ย 

ย