About The Role
You handle the queue of reports submitted by external security researchers. For each one you attempt to reproduce the issue, assign a severity based on the demonstrated impact, and rewrite it so that an engineer can act on it without further questions. You are also the point of contact for the researcher, which includes explaining clearly when a report is a duplicate, out of scope, or not a vulnerability.
What you will do
- Reproduce reports and settle severity with evidence
- Rewrite findings so an engineer can act without asking questions
- Keep researchers informed, including when the answer is no
What they ask for
- Strong web security fundamentals
- Fast, fair judgement on severity
- Writes well enough to defuse an argument
Nice to have
- Bug bounty experience from the researcher side
- CVSS fluency