Stripe
Security Analyst, Bug Bounty
Remote, North America · Full-time
Sponsorship not specified$121k-$182kDetected 16 hours ago
PythonRubyAWSGCPData AnalysisCybersecurityCustomer SupportCommunicationBurp Suite
About the role
- The bug bounty program is an important pillar of this mission, acting as a critical line of defense in Stripe's security "immune system."
Responsibilities
- Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers
- Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders
- Provide tactical support for vulnerability management triage processes to augment the team as needed
- Prepare and implement improvements to the overall bug bounty program
- You'll own the overall effectiveness of Stripe's bug bounty program with autonomy to implement continuous improvements (e.g., researcher campaigns, scoring transparency).
- A core aspect of this role is developing a deep understanding of Stripe and acquired company products, assets, and their configuration to effectively assess and prioritize vulnerabilities.
Requirements
- Proven ability to follow bug reports and accurately triage security vulnerabilities
- Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
- Ability to think like an attacker to understand the impact of vulnerabilities
- Experience in one of the following areas
- Knowledge of Stripe products and general security expertise
- That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
- We're looking for someone who meets the minimum requirements to be considered for the role.
Nice to have
- Prior participation in or experience with bug bounty programs
- Experience analyzing source code for security vulnerabilities
- Proficiency in scripting languages (e.g., Python, Ruby) for automation
- Familiarity with cloud-based services (e.g., AWS, GCP)
- Certifications such as OSWA or BSCP
- While you would be welcome to come into the office for team/business meetings, on-sites, meet-ups, and events, our expectation is you would regularly work from home rather than a Stripe office.
Compensation
- The annual US base salary range for this role is $121,000 - $181,600.
Benefits
- The preferred qualifications are a bonus, not a requirement.
Company info
- About Stripe
- Stripe is a financial infrastructure platform for businesses. Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
- About the team
- In this role, you'll join Stripe's Vulnerability Management team, whose mission is to "Surface vulnerabilities at scale across Stripe." Our vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission, acting as a critical line of defense in Stripe's security "immune system."
- Stripe is a financial infrastructure platform for businesses.
- Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities.
- Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead.
- In this role, you'll join Stripe's Vulnerability Management team, whose mission is to "Surface vulnerabilities at scale across Stripe." Our vision is to create a culture of continuous excellence in managing vulnerabilities.
- At Stripe, we're looking for people with passion, grit, and integrity.
- Your skills and passion will stand out-and set you apart-especially if your career has taken some extraordinary twists and turns.
- At Stripe, we welcome diverse perspectives and people who think rigorously and aren't afraid to challenge assumptions.
This listing is sourced directly from Stripe's careers page and normalized into a canonical job model.