Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels
Independently validate, reproduce, severity-score, and document findings
Identify duplicates and maintain a clean vulnerability records pipeline
Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC)
Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation
Provide detailed reproduction steps, proof-of-concepts, and technical analyses
Track SLAs, remediation progress, regression testing, and systemic improvements
Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance
Lead the coordinated vulnerability disclosure process for internal and external findings
Negotiate disclosure timelines with researchers and partners
Coordinate CVE assignments and publications, and prepare customer/public advisories
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds