Security Analyst, Bug Bounty

at Stripe
USD 144,400-216,600 per year
MIDDLE
✅ Remote

Tech Stack

AWS @ 2 Communication @ 5 Data Analysis GCP @ 2 OWASP @ 2 Payments Python @ 5 Ruby @ 5 Security @ 3

Details

Who We Are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.

About the Team

You’ll join Stripe’s Vulnerability Management team, whose mission is to surface vulnerabilities at scale across Stripe. The team’s vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission and a critical line of defense in Stripe’s security immune system.

Responsibilities

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly and effectively with security researchers to follow up on unclear reports, improve report clarity, and increase engagement with top hackers.
  • Understand the root cause of security vulnerabilities to help product and engineering teams fix them and advise on appropriate mitigation strategies.
  • Drive submissions through their full lifecycle to resolution, coordinating with product and engineering stakeholders.
  • Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation.
  • Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives.
  • Provide tactical support for vulnerability management triage processes as needed.
  • Prepare and implement improvements to the overall bug bounty program, including researcher campaigns and scoring transparency.
  • Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation.
  • Develop a deep understanding of Stripe and acquired company products, assets, and configurations to effectively assess and prioritize vulnerabilities.

Requirements

Minimum Requirements

  • Proven ability to follow bug reports and accurately triage security vulnerabilities.
  • Familiarity with web security issues and exploit methodologies, including OWASP Top 10 and CWEs.
  • Competence with offensive security tools, such as Burp Suite and custom scripting.
  • Ability to think like an attacker to understand the impact of vulnerabilities.
  • Proficiency in clear communication and conveying technical concepts to various stakeholders.
  • Experience in bug bounty programs, triaging security vulnerability reports, knowledge of Stripe products, or general security expertise.

Preferred Qualifications

  • Experience in technical support, operations, or similar roles involving technical systems.
  • Prior participation in or experience with bug bounty programs.
  • Experience analyzing source code for security vulnerabilities.
  • Proficiency in scripting languages such as Python or Ruby for automation.
  • Familiarity with cloud-based services such as AWS or GCP.
  • Certifications such as OSWA or BSCP.

More jobs at Stripe

Similar jobs