3+ years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
Strong understanding of CVSS v3.1 scoring and hands-on experience applying it to real-world vulnerabilities.
Proficiency in common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
Company:
Our client is a global leader in creative software, offering innovative tools for digital media creation, design, and marketing.
About the Role:
Client is seeking a Product Security Engineer to support our Bug Bounty program on a 6-month contract engagement, backfilling a team member on leave. You will be the frontline responder for external vulnerability reports submitted through the program, working closely with internal engineering and security teams to ensure timely, accurate triage and resolution.
Responsibilities:
Triage incoming vulnerability reports submitted via the bug bounty platform, assessing validity, impact, and scope.
Assign CVSS scores and severity ratings accurately, following internal severity guidelines and industry standards.
Reproduce proof-of-concept (PoC) exploits to validate reported vulnerabilities across web, API, and mobile surfaces.
Communicate clearly and professionally with external researchers: request clarifications, provide status updates, and manage expectations.
Coordinate with product engineering teams to route confirmed vulnerabilities for remediation.
Identify duplicate, out-of-scope, or informational reports and close them with clear, respectful explanations.
Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
Flag systemic or critical findings to Bug Bounty team for escalation as needed.
Required Qualifications:
3+ years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
Strong understanding of CVSS v3.1 scoring and hands-on experience applying it to real-world vulnerabilities.
Proficiency in common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts.
Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and responsible disclosure processes.
Solid written communication skills able to write clear, constructive responses to researchers of all skill levels.
Familiarity with attacker techniques used by external researchers against LLM systems and generative AI products.
Knowledge of application security vulnerabilities (OWASP Top 10) and mitigation techniques.
Nice to Have:
Experience with cloud environments (AWS, Azure, GCP) and API security testing.
Hands-on experience in penetration testing of AI/ML and LLM-powered products, including chat interfaces, agentic workflows, and inference APIs.
Prior participation in bug bounty programs as a researcher.
Familiarity with OWASP Top 10, CWE taxonomy, and CVE assignment processes.
Background working within a large enterprise or SaaS security organization.
BENEFITS SUMMARY: Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate or annual salary only, unless otherwise stated. In addition to base compensation, full-time roles are eligible for Medical, Dental, Vision, Commuter, and 401K benefits with company matching.
IND123
Numbers & Facts
Location
Lehi, UT
Salary
$74–$84.51 Per Hour
Skills
(XSS) Cross Site Scriptingunmatched
Amazon Web Services (AWS)unmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Artificial Intelligence (AI)unmatched
Authenticationunmatched
Calibrationunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Securityunmatched
Digital Mediaunmatched
Documentationunmatched
Enterprise Protectionunmatched
GCP (Good Clinical Practices)unmatched
Industry Standardsunmatched
Injectionsunmatched
Internet Securityunmatched
Marketingunmatched
Microsoft Windows Azureunmatched
Online Coursesunmatched
Penetration Testingunmatched
Product Engineeringunmatched
Proof of Conceptunmatched
Research Skillsunmatched
SQL (Structured Query Language)unmatched
Scripting (Scripting Languages)unmatched
Security Attacksunmatched
Software as a Service (SaaS)unmatched
Taxonomiesunmatched
Time Managementunmatched
Web Browsersunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.