Junior Security Engineer
Sydney, Australia / Asia Pacific
Bugcrowd
Bugcrowd teams with elite security researchers to reduce risk & improve security ROI through our bug bounty, pen testing, & vulnerability disclosure programs.Bugcrowd is the world’s #1 crowdsourced security company. Our award-winning platform combines actionable, contextual intelligence with the skill and experience of the world’s most elite hackers to help leading organizations solve security challenges, protect customers, and make the digitally connected world a safer place.
This is a Remote role
A successful candidate will be passionate about security and be hungry to learn more, while adapting to a constantly changing environment.
Description
The Junior Security Engineer’s role is to aid the security efforts of Bugcrowd, while proactively making changes to further improve our security posture. To achieve this goal, we require a motivated team who are willing to push their own boundaries and step out of their comfort zones. You will be challenged on a regular basis, especially because you are the last line of defence for one of the largest crowdsourced security platforms! The Junior Security Engineer will receive mentoring from multiple senior security professionals and will work closely with these professionals on a daily basis.
Responsibilities
- Security Architecture - Working with developers to uplift the current security controls and architecting solutions
- Risk Management - Assess the risk behind security issues, track core metrics
- Pen Testing / Red Team - Performing penetration tests and red teams of Bugcrowd assets (and vendors)
- Operations / Incident Response - Aid with the process of Incident Response, security operational activities when required
Position Requirements
- Familiarity with Pentesting techniques
- Knowledge of OWASP Top 10
- Basic knowledge of Incident Response
- Knowledge of threat intelligence
- Ability to understand a vulnerability and work with developers to patch it
- Scripting knowledge of at least one of: Python, JavaScript, Ruby
- Great communicator who is comfortable communicating across multiple teams
- Self motivated and organised - must be able to operate from a calendar and be punctual
- Some cloud experience (AWS preferred)
- Basic understanding of Identity and Access Management (IAM)
- Ability to figure things out themselves (look at configurations, learn what they mean, and solve problems)
- Has the desire to be self-sufficient and strives towards it
- Basic red team knowledge
- Familiarity with git and pull requests is a must
- Familiarity with a ticketing system / issue tracking system is a must (e.g: Jira)
Formal Education
The Junior Security Engineer will have a bachelor’s degree / certifications (or equivalent) and 2 years of experience in a similar role or its equivalent.
Culture:
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
Perks:
- Competitive salary and stock options
- Opportunities to attend & host relevant conferences & meetups
- Flexible vacation time
- Mental Health Days
- Exceptional medical, dental & vision coverage
- Generous allowance to build the workstation that suits you
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring. We are a supportive & collaborative team who understand that reaching Bugcrowd’s potential depends on the happiness of the employee.
Background Checks:
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Tags: AWS Cloud IAM Incident response JavaScript Jira OWASP Pentesting Python Red team Risk management Ruby Scripting Threat intelligence Vulnerabilities
Perks/benefits: Career development Competitive pay Conferences Equity Flex hours Flex vacation Health care
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open CISM-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open APIs-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs