Base Career helps you apply smarter for this job.
Key skills for this role
Vulnerability triage is often treated as queue work: read the report, check the scope, set a severity, move it on. We are building this role differently. As Security Triage Analyst you own the first layer of judgement on every report that reaches Verda – what is real, what matters, what needs more evidence, and what happens next – reproducing findings where it is safe to, assessing impact, and writing them up so engineers can act.
The environment is unusual: Verda runs multi-tenant GPU infrastructure, customer-facing cloud services, APIs, and management planes, so a report that looks routine elsewhere can matter more here because of tenant isolation, customer impact, or infrastructure access.
You will work closely with Security, Engineering, Infrastructure, external triage partners, and researchers, and you will help improve how vulnerability handling works as the volume grows.
Cash and equity compensation along with various fringe benefits (healthcare, lunch, wellbeing, and more).
Profitable operations with rapid, sustained growth.
40+ nationalities, with 6 different ones on the management team.
A real chance to make an impact and work alongside world class engineers, researchers, and partners across the global AI ecosystem.
Vulnerability triage is often treated as queue work: read the report, check the scope, set a severity, move it on. We are building this role differently. As Security Triage Analyst you own the first layer of judgement on every report that reaches Verda – what is real, what matters, what needs more evidence, and what happens next – reproducing findings where it is safe to, assessing impact, and writing them up so engineers can act.
The environment is unusual: Verda runs multi-tenant GPU infrastructure, customer-facing cloud services, APIs, and management planes, so a report that looks routine elsewhere can matter more here because of tenant isolation, customer impact, or infrastructure access.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
London, GBR
London, GBR
London, GBR
London, GBR
London, GBR
London, GBR
London, GBR
London, GBR
You will work closely with Security, Engineering, Infrastructure, external triage partners, and researchers, and you will help improve how vulnerability handling works as the volume grows.
5+ years of previous experience in vulnerability triage, application security, penetration testing, security operations, or a closely related security role
Ability to understand and validate technical vulnerability reports, including incomplete, unclear, automated, or poorly written ones
Practical knowledge of web application and API security: authentication, authorisation, access control, CORS (Cross-Origin Resource Sharing), rate limiting, SSRF (Server-Side Request Forgery), injection issues, file handling, and business logic flaws
Enough infrastructure and cloud security depth to reason about network exposure, internal services, storage, identity, Kubernetes, management interfaces, and multi-tenant environments
Ability to reproduce findings safely using tools such as Burp Suite, curl, browser developer tools, API clients, logs, and basic scripting
Sound judgement on severity and impact using CVSS or a comparable model – telling the finding that matters from the one that only looks serious at first glance
Strong attention to detail when comparing duplicates, checking evidence, and reviewing reproduction steps
Professional handling of external researchers, including unclear, automated, duplicated, disputed, or appealed reports
Comfortable where there is no runbook yet, with the curiosity to learn an environment most security people have not seen
Experience managing or operating a bug bounty or vulnerability disclosure platform such as YesWeHack, HackerOne, or Bugcrowd, including researcher reward models and severity appeals
Background in cloud service providers, hosting, infrastructure, or multi-tenant platforms
Familiarity with Kubernetes, object storage, IAM (Identity and Access Management), VPNs (Virtual Private Networks), APIs, and customer-facing cloud consoles
Basic Python, Bash, or other scripting for reproducing issues and automating repetitive triage tasks
Experience with AI-assisted security testing, or reviewing AI-generated vulnerability reports
Relevant certifications
Location: London, UK
Hybrid mode: Working 3 days a week from our London office
Employment type: Full time and permanent
We're building fast and this role needs the right person behind it. There's no artificial deadline, but when we find who we're looking for, we move. If this sounds like your next move, apply now.
Please submit your application through our Careers page. We don't accept applications sent by email.
European AI cloud provider delivering on-demand GPU infrastructure to developers and organizations from renewable-powered Finnish data centers.
Visit company websiteJobs and hiring trendsFull-time
Senior · 5+ years experience
Hybrid
Apply faster on company sites with our extension.