HackerOne
Visit websiteProduct Security Analyst
$135,000 – $155,0003+ yearsRemote
- Technical Services
- United States
- Full time
- Yesterday
About the role
As a Product Security Analyst, you will join the Technical Services organization to work with security researchers to help customers identify and remediate impactful vulnerabilities. You will play a critical role in validating, reproducing, and communicating security findings across bug bounty and vulnerability disclosure programs. This role offers an opportunity to deepen technical expertise in web and mobile application security while collaborating with globally distributed teams.
Responsibilities
- Evaluate vulnerability reports submitted by security researchers to determine validity, severity, exploitability, and business impact.
- Independently reproduce reported vulnerabilities across web and mobile applications to validate findings and identify root causes.
- Collaborate directly with security researchers to gather missing information and improve report quality.
- Create concise, technically accurate summaries for validated findings, including reproduction steps, impact analysis, and remediation guidance.
- Contribute to an AI-First approach by leveraging automation and AI-enabled workflows to improve operational efficiency.
- Partner cross-functionally with Technical Services teammates and customer-facing teams to ensure timely handling of vulnerabilities.
Required skills
- Security testing
- Vulnerability research
- Ethical hacking
- OWASP Top 10
- Burp Suite
- CVSS
Nice to have
- Bug bounty programs
- Vulnerability disclosure programs
- Scripting
- Automation
Qualifications
- 3+ years of hands-on experience performing security testing, vulnerability research, or ethical hacking on web and mobile applications
Benefits
- Health insurance
- Life insurance
- Disability insurance
- Equity stock options
- Retirement plans
- Paid public holidays
- Unlimited PTO
- Paid maternity and parental leave
- Employee Assistance Program
About the Company
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems.