Security Analyst, Bug Bounty
Stripe
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
In this role, you’ll join Stripe’s Vulnerability Management team, whose mission is to “Surface vulnerabilities at scale across Stripe.” Our vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission, acting as a critical line of defense in Stripe’s security “immune system.”
What you’ll do
We seek a highly technical and detail-oriented Security Analyst to join our team, focusing on the front lines of bug bounty triage and researcher engagement. In this role, you’ll be responsible for the end-to-end lifecycle of security vulnerability reports from our bug bounty program. You’ll own the overall effectiveness of Stripe’s bug bounty program with autonomy to implement continuous improvements (e.g., researcher campaigns, scoring transparency).
You’ll play a key role in understanding the root cause of vulnerabilities, coordinating timely resolutions, and directly impacting the security posture of Stripe’s products. A core aspect of this role is developing a deep understanding of Stripe and acquired company products, assets, and their configuration to effectively assess and prioritize vulnerabilities.
Responsibilities
- Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program
- Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers
- Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies
- Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders
- Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation
- Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives
- Provide tactical support for vulnerability management triage processes to augment the team as needed
- Prepare and implement improvements to the overall bug bounty program
- Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- Proven ability to follow bug reports and accurately triage security vulnerabilities
- Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
- Competent in offensive security tools (e.g., Burp Suite, custom scripting)
- Ability to think like an attacker to understand the impact of vulnerabilities
- Proficient in clear communication, conveying technical concepts to various stakeholders
- Experience in one of the following areas
- Bug bounty program or triaging security vulnerability reports
- Knowledge of Stripe products and general security expertise
Preferred qualifications
- Experience in technical support, operations, or similar roles with technical systems exposure
- Prior participation in or experience with bug bounty programs
- Experience analyzing source code for security vulnerabilities
- Proficiency in scripting languages (e.g., Python, Ruby) for automation
- Familiarity with cloud-based services (e.g., AWS, GCP)
- Certifications such as OSWA or BSCP
- ...the Role This is our first dedicated security hire, and it's a rare chance to define... ...early engineer, not just a user. You helped secure it from early design or during major... ...you've run security programs in practice: bug bounty, pentest engagements, working with external...SuggestedFull timeRemote work
$130k - $145k per year
...their inbound pipeline motion. Overview: We are seeking a Security Analyst who is passionate about safeguarding systems, data, and people... ..., helping employees remain productive while operating in a secure environment. This role blends hands-on security operations,...SuggestedRemote job- ...Beyond that, you bring: Extensive experience in hospitality or hotel technology — as a journalist, trade publication editor, industry analyst, or content strategist embedded in the space Exceptional writing: clear, specific, and authoritative at the sentence level — your...SuggestedInternshipWork at officeLocal areaRemote workWork from homeHome officeShift workWeekend work
$16 per hour
...Discount on food at our restaurant Reporting to the Property Manager, the Security Agent is responsible for safeguarding our assets, staff, and visitors. You will be tasked with maintaining a safe and secure environment by implementing preventive measures and responding...SuggestedFull timeFlexible hours$145k - $165k per year
...migration, and ensure our platform delivers exceptional performance and security for thousands of properties worldwide. Your work will directly... ...and scalability for our distribution platform Architect secure solutions for handling financial transactions and sensitive...SuggestedLong term contractFull timeWork at officeLocal areaRemote workWork from homeWorldwideHome officeWeekend work- ...departments. This is a high profile and impactful, hands-on position that will require grit. Work together with our developers and privacy/security experts to help us take our browser to the next level. Requirements ~5+ years experience with testing software ~ Strong...Full timeWork at officeRemote workHome office
- ...engineering, applied AI, and developer experience to make it easier for teams across Zapier to build with LLMs and ML systems in a scalable, secure, and production-ready way. Your work will focus heavily on LLM Ops and ML Ops : improving how models are accessed, monitored,...Full timeRemote work
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Full timeRemote work
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Full timeRemote workFlexible hours
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Full timeRemote work
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Full timeRemote work
- ...de plusieurs types d’audit (ex. : fournisseurs, sites d’investigateur, dossiers principaux de l’essai, gestion de données, rapport de sécurité et laboratoires). Excellente connaissance des exigences réglementaires des BPx. Connaissance de la terminologie médicale et...Daily paidContract workTemporary workWork at office
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Remote work
$175k - $200k per year
...complex, distributed systems at scale You take pride in code quality and test infrastructure while prioritizing execution speed, security, and the end-user experience Preferred You have a passion for cryptocurrency and blockchain technologies Data manipulation -...Local areaWorldwideFlexible hours- ...international teams to keep EnterpriseOne 9.2 running reliably. What You’ll Take On Daily Operations and Security: Act as the Tier 1 and 2 analyst for our global users. This includes managing JDE profile maintenance, security setup and terminations. Experience...Permanent employmentFull timeCasual work
- ...After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to...Full timeRemote work
$145k - $260k per year
...design, coding, code review, unit/integration testing, bug fixing, and code/API documentation. Collaborate closely... ...offer an enterprise plan with features around privacy, security and environment management (e.g. secure distribution and management of API keys). These larger...Remote jobRemplacementInternshipWork at officeImmediate startFlexible hours- ...teams to align on customer goals, stakeholders, success criteria, timelines, and account context Capture and synthesize product gaps, bugs, workflow patterns, technical blockers, and customer feedback for Product and Engineering teams Create reusable deployment assets...Minimum wageFull timeLocal areaRemote workFlexible hours
- ...Assistant Coordinate delivery across Data Engineering, DS ICs, Security, IT, and business stakeholders (Sales, Product, Finance,... ...BI tooling (Hex, Sigma), and AI-powered query interfaces (Cortex Analyst, RAG) at a program level ~ A track record of driving adoption...Minimum wageFull timeLocal areaRemote workFlexible hoursShift work
$100k per year
...from a firmware perspective. Debug complex hardware-software interactions, including signal integrity issues and protocol-level timing bugs. What You Will Learn What it means to shape AI acceleration hardware and networking infrastructure from the ground up. How...Permanent employment- ...behavior and sign‑off criteria for silicon. Have impact measured through coverage metrics achieved, quality and reproducibility of bugs found, and robustness of the verification environment you help build. What You Will Learn End‑to‑end SoC design and verification...Permanent employmentSummer workInternshipWork at office
- ...analytics buyer, and our competitive differentiation. You will: Be the expert on our data analytics buyers — understand how data analysts, analytics engineers, and BI practitioners evaluate and adopt tools, and translate those insights into product roadmap recommendations...
$200k - $276k per year
...into technical solutions Collaborate with Data Scientists and Analysts to enable advanced analytics, machine learning, and business... ...initiatives and embedded reporting capabilities Engage with Security and Compliance teams to ensure data governance and regulatory requirements...Remote jobLong term contractWorldwideHome office- ...etc. Click here to view ALL of our open jobs. What are we known for and how do we help? Helping talented professionals secure new, exciting and rewarding career opportunities Treating each unique individual with professionalism, respect and integrity Meeting...Permanent employmentFull timeFor subcontractorRemote workRelocation package
- ...Intelligence, AI & Machine Learning, Intelligent Automation, Enterprise Platforms and Engineering, with a specialized focus on National Security and Federal Financial programs. We are dedicated to delivering forward-thinking solutions that accelerate the critical missions of...Full timeContract workWork at officeRemote work
- ...mobile development practices. This role sits within the engineering organization and focuses on building performant, maintainable, and secure mobile applications. The Mobile Engineer will contribute to architecture decisions, implement new product capabilities, and ensure...Full timeLocal areaFlexible hours
$100k per year
...Technology you will be responsible for building and scaling the internal technology foundation that helps the company move fast, stay secure, and operate reliably across teams and geographies. This is a high-impact leadership role for someone who can own enterprise systems,...Permanent employment- ...our work with public safety agencies, this position requires compliance with the FBI's Criminal Justice Information Services (CJIS) Security Policy. Candidates must successfully pass a comprehensive, fingerprint-based background check. Please note that specific customer contracts...InternshipWork from home
- ...Telesat (Nasdaq and TSX: TSAT) is a leading global satellite operator, providing reliable and secure satellite-delivered communications solutions worldwide to broadcast, telecommunications, corporate and government customers for over 55 years. Backed by a legacy of engineering...Work at officeWorldwide
- ...risk assessments to the Director, Deployments. Ensure all team members operating in regulated environments are in compliance with security clearance requirements and applicable data handling standards. Support pre-sales and scoping conversations where deployment or integration...InternshipWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst, Bug Bounty. Be the first to apply!

