Global Payments logo
Global PaymentsPosted 3 weeks ago

Bug Bounty Analyst

On-siteLondon, England, United Kingdom or Dublin, Leinster, Ireland

Full TimeEnterprise

Job Summary

Assess, coordinate, and remediate findings reported through the Bug Bounty Program from whitehat researchers. Support ticket triage, ensure findings are reported to remediation owners, and oversee remediation efforts and retest. Work closely with lines of business and security champions to mature the program, assess severity using CVSS, and develop mitigation plans. Analyze scanner visibility gaps, identify missing security controls, and document risks with Risk Management teams while maintaining knowledge of PCI, HIPAA, GDPR, and NIST frameworks. Collaborate with Legal and Privacy Offices for critical data risks and follow runbooks for day-to-day activities.

Required Qualifications

  • Bachelor's degree in Computer Science, Info Security, or related field
  • Relevant work experience in a related field
  • Typically Minimum 2 Years Relevant Experience with Vulnerability Management or involved in Bug Bounty Program handling
  • Knowledge of network operations or engineering or system administration on Unix, Linux, MAC, or Windows
  • common security operations
  • intrusion detection systems
  • Security Incident Event Management systems
  • Penetration Testing
  • Web Application assessment
  • Secure Coding practices
  • Cloud Technologies
  • Knowledge of industry standard security compliance programs PCI, GDPR, NIST Cyber Security Framework etc.

Desired Qualifications

  • Professional security certifications such as CompTIA Security+ or CompTIA PenTest, Systems Security Certified Practitioner (SSCP), or CISM, or CISA, or CEH
  • Certified Secure Software Lifecycle Professional (CCSLP)
  • GIAC Web Application Defender (GWEB)
  • eJPT
  • OSCP
  • Experience working with ticketing systems such as ServiceNow and/or JIRA
  • Strong verbal and written communication skills
  • Attention to detail
  • Demonstrated ability to effectively communicate ideas and persuade others to accomplish challenging goals and objectives
  • Ability to facilitate meetings and enable discussions that lead to resolution and communicate results
  • Vulnerability Management - knowledge with a proven record of assessing application and infrastructure vulnerabilities; understanding exploit methodologies
  • Developing professional expertise, applies company policies and procedures to resolve a variety of issues
  • Works on problems of moderate scope where analysis of situations or data requires a review of a variety of factors
  • Exercises judgement within defined procedures and practices to determine appropriate action
  • Builds productive internal/external working relationships
  • Normally receives general instructions on routine work; however can work independently where required
  • Continued self-education of new and emerging threats and vulnerabilities and relevant processes, controls, or technologies to mitigate them

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce