This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This job role is directly responsible for handling the day-to-day operations of the HSBC Bug Bounty Program. As part of this role, you will act as the escalation point of contact for any incoming security vulnerabilities received through the Bug Bounty Program and are expected to be an experienced pentester.
Job Responsibility:
Analyze, assess and respond to the security vulnerabilities received as part of Bug Bounty Program
Research and reproduce the security vulnerabilities
Perform the root cause analysis of the security vulnerabilities
Effectively communicate with the external security researchers
Work closely with the appropriate stakeholders across departments to help them understand the risks, and the track remediation
Drive improvements including tooling, automation, and setting up processes
Help drive the maturity of Bug Bounty Program by continuously improving quality of our services and removing inefficiencies, in line with wider Cybersecurity strategy
Advise on vulnerability remediation, control implementation and secure development practices
Requirements:
At least 4 years of prior demonstrable hands-on experience in penetration testing
Solid understanding of the platform security models for iOS and Android platforms
Excellent understanding of platform-specific security risks, common vulnerabilities for mobile applications, common risks in financial applications
Practical knowledge of penetration testing of widely understood infrastructure, web and mobile technologies, using manual and automated testing methods
Excellent TCP/IP knowledge and understanding of security implications/issues
Strong web application testing experience
Proven programming/scripting skills
Strong understanding of applied use of cryptography in application development
What we offer:
Annual performance-based bonus
Additional bonuses for recognition awards
Multisport card
Private medical care
Life insurance
One-time reimbursement of home office set-up (up to 800 PLN)