Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 2
Communication @ 5
Data Analysis
GCP @ 2
OWASP @ 2
Payments
Python @ 5
Ruby @ 5
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.
About the Team
The Vulnerability Management team’s mission is to surface vulnerabilities at scale across Stripe and create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important part of this mission and acts as a critical line of defense in Stripe’s security system.
Responsibilities
- Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
- Communicate clearly and effectively with security researchers to follow up on unclear reports, improve report clarity, and increase engagement with top hackers.
- Understand the root causes of security vulnerabilities to help product and engineering teams fix them and advise on appropriate mitigation strategies.
- Drive submissions through their full lifecycle to resolution, coordinating with product and engineering stakeholders.
- Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation.
- Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives.
- Provide tactical support for vulnerability management triage processes as needed.
- Prepare and implement improvements to the overall bug bounty program, including researcher campaigns and scoring transparency.
- Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation.
- Develop a deep understanding of Stripe and acquired company products, assets, and configurations to assess and prioritize vulnerabilities effectively.
Requirements
- Proven ability to follow bug reports and accurately triage security vulnerabilities.
- Familiarity with web security issues and exploit methodologies, including the OWASP Top 10 and CWEs.
- Competence with offensive security tools such as Burp Suite and custom scripting.
- Ability to think like an attacker and understand the impact of vulnerabilities.
- Proficiency in clear communication and conveying technical concepts to various stakeholders.
- Experience in bug bounty programs, triaging security vulnerability reports, knowledge of Stripe products, or general security expertise.
Preferred Qualifications
- Experience in technical support, operations, or similar roles involving exposure to technical systems.
- Prior participation in or experience with bug bounty programs.
- Experience analyzing source code for security vulnerabilities.
- Proficiency in scripting languages such as Python or Ruby for automation.
- Familiarity with cloud-based services such as AWS or GCP.
- Certifications such as OSWA or BSCP.
More jobs at Stripe
Enterprise Risk Management (ERM) Program & Automation Lead, MALPB
Stripe · United States
USD 165,600-248,400 per year
Staff Software Engineer, Release Engineering
Stripe · Seattle, United States
USD 224,000-336,000 per year
IT SOX Controls Specialist
Stripe · South San Francisco, United States, New York City, United States, Seattle, United States
USD 135,000-202,400 per year
Staff Software Engineer, Issuing
Stripe · South San Francisco, United States, New York City, United States, Seattle, United States
USD 224,000-336,000 per year
Staff Full Stack Engineer, Payments Intelligence
Stripe · Seattle, United States
USD 224,000-336,000 per year
Similar jobs
Security Analyst, Bug Bounty
Stripe · United States
USD 144,400-216,600 per year
Security Engineer, Privy
Stripe · New York City, United States
USD 196,900-295,300 per year
Software Engineer, Secrets Infrastructure
Stripe · United States
USD 173,000-259,600 per year
AI Engineer
Stripe · Chicago, United States
USD 126,600-235,300 per year
Engineer, Security Operations & Engineering
Collibra · United States
USD 116,000-145,000 per year
Senior Product Security Engineer
Collibra · United States
USD 168,000-210,000 per year
Senior Product Security Engineer
Collibra · Raleigh, United States
USD 168,000-210,000 per year
Application Security Engineer
SpaceXAI · Palo Alto, United States
USD 100,000-258,000 per year