Base Career helps you apply smarter for this job.
Key skills for this role
Assess and support severity assignment on reported vulnerabilities/bugs in line with the Common Vulnerability Scoring System (CVSS)
Effectively communicating vulnerability findings to stakeholders, including technical and non-technical audiences
Developing strategies to address identified vulnerabilities, including mitigation plans and timelines
Coordinate the remediation of findings from the organisation’s Bug Bounty & Vulnerability Disclosure Programs working directly with whitehat researchers
Analyze findings to understand if our vulnerability scanners failed to identify them and work with the relevant to address any visibility gaps
Identify missing security controls that could have mitigated the Bug Bounty finding and ensure correction is tracked to completion
Mature the program through the onboarding of new assets
Works closely with Risk Management teams to document identified risks and issues highlighted through Bug Bounty Program
Maintains a working knowledge of key data security frameworks and regulations such as PCI (Payment Card Industry)/Logical Security guidelines and models, HIPPA (Health Insurance Portability and Accountability Act), (GDPR) General Data Protection Regulation, PII (Personally Identifiable Information), NIST CSF (Cyber Security Framework).
Collaborates with Legal and Privacy Offices when critical data is at risk as a result of a Bug Bounty finding
Maintain and follow runbooks for day-to-day activities
Minimum Qualifications
Relevant Experience or Degree in: Bachelor's degree in Computer Science, Info Security, or related field. Or relevant work experience in a related field.
Typically Minimum 2 Years Relevant Experience with Vulnerability Management or involved in Bug Bounty Program handling
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Montréal, CAN
Toronto, CAN
Leicester, GBR
Sydney, AUS
Montréal, CAN
Toronto, CAN
Leicester, GBR
Leicester, GBR
Sydney, AUS
Chatswood, AUS
Brisbane, AUS
Sydney, AUS
Knowledge of network operations or engineering or system administration on Unix, Linux, MAC (Message Authentication Code), or Windows; common security operations, intrusion detection systems, Security Incident Event Management systems, Penetration Testing, Web Application assessment, Secure Coding practices, Cloud Technologies.
Preferred Qualifications
Professional security certifications such as CompTIA Security+ or CompTIA PenTest, Systems Security Certified Practitioner (SSCP), or CISM(Certified Information Security Manager), or CISA(Certified-Information-Systems-Auditor) or CEH (Certified Ethical Hacker)
Certified Secure Software Lifecycle Professional (CCSLP) or GIAC Web Application Defender (GWEB) or eJPT (eLearnSecurity Junior Penetration Tester), OSCP (Offensive Security Certified Professional)
Knowledge of industry standard security compliance programs PCI (Payment Card Industry), GDPR (General Data Protection Regulation), NIST Cyber Security Framework etc.)
Experience working with ticketing systems such as ServiceNow and/or JIRA
Provides payment technology and software solutions for global commerce.
Visit company websiteJobs and hiring trendsFull-time
Entry · 2+ years experience
Hybrid
Apply faster on company sites with our extension.