Vulnerability Management and Bug Bounty Senior Analyst Internet & Ecommerce - San Jose, CA at Geebo

Vulnerability Management and Bug Bounty Senior Analyst

DescriptionTikTok is the leading destination for short-form mobile video.
Our mission is to inspire creativity and bring joy.
TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo.
Why Join UsCreation is the core of TikTok's purpose.
Our platform is built to help imaginations thrive.
This is doubly true of the teams that make TikTok possible.
Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.
To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team.
Status quo? Never.
Courage? Always.
At TikTok, we create together and grow together.
That's how we drive impact - for ourselves, our company, and the communities we serve.
Join us.
The Global Security Organization provides industry-leading cyber-security and business protection services to TikTok globally.
Our organization employs four principles that guide our strategic and tactical operations.
Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first.
Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development.
We constantly work towards a sustainable world-class security capability.
Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile.
Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk.
The Vulnerability Management and Bug Bounty Senior Analyst is tasked with the day to day activities of the Vulnerability Management Team.
They manage and continuously improve the external bug bounty program.
They should be aware of current policies and procedures and ensure they are being followed properly.
The senior analyst should have hands on experience with vulnerability management tools and be able to mentor and advise other team members.
Tasks and Responsibilites:
- Develop and implement a comprehensive vulnerability management strategy for web and mobile applications.
- Manage and continuously improve the external bug bounty program, including setting program scope, rules of engagement, and incentives for researchers to participate.
- Triage reported vulnerabilities from the bug bounty program, prioritize them based on risk and impact assessments, and coordinate with internal development teams for timely resolution.
- Regularly evaluate the performance and results of the bug bounty program, identify areas for improvement, and implement enhancements to mature the program over time.
- Collaborate with external bug bounty platforms or vendors to ensure the program's effectiveness and efficiency.
- Actively engage with external security researchers, fostering a collaborative relationship to encourage their participation in the bug bounty program and to facilitate effective communication throughout the vulnerability disclosure process.
- Conduct manual verification of security issues identified through automated scans, manual tests or reported by external researchers to validate their severity and impact.
- Collaborate with cross-functional teams to prioritize and address identified vulnerabilities based on risk and impact assessments.
- Track and report on the status of vulnerability remediation efforts, including providing regular updates to stakeholders.
- Stay informed about emerging security threats, industry best practices, and relevant regulations to continuously improve the effectiveness of our vulnerability management program.
- Mentor and provide guidance to junior team members on vulnerability management processes and techniques.
- Evaluate vulnerabilities based on prioritization criteria - Investigate persistent vulnerabilities - Coordinate and communicate with cross-functional teams throughout the VM lifecycle - Facilitate exception handling and escalation - Support regulatory compliance monitoring and reporting- Review and optimize scan templates to ensure complete coverage of environment - Support treatment and remediation activities with identified points of contact and system owners - Provide risk analysis for identified vulnerabilities and system change requests - Develop processes and document procedures for use by other team members and to enhance efficiencies- Maintain regular communication with Vulnerability Management Lead and organizational management for collaboration, process optimization, tools tuning, and information sharingQualificationsMinimum
Qualifications:
- Hands-on experience with vulnerability assessment tools, penetration testing methodologies, and secure coding practices.
- Experience managing external bug bounty programs and working with security researchers.
- Strong understanding of web and mobile application security vulnerabilities, such as OWASP Top 10.
- Excellent communication skills, with the ability to effectively collaborate with both technical and non-technical stakeholders.
- Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions.
- Ability to work alongside other security functions to determine vulnerability scoring and impact- Strong analytical and problem-solving skills and Project management experiencePreferred
Qualifications:
- Bachelor s Degree or industry equivalent work experience in vulnerability management or application security testing - 5 years of experience in vulnerability management, penetration testing, or related fields - CISSP, CEH, OSCP, or equivalent certification - Familiarity with vulnerability management across SaaS and IaaS cloud platforms (e.
g.
, AWS, Google Cloud, etc.
) - Working knowledge/experience with Python, SQL and REST APIs- Ability to handle ambiguity and collaborate with a global team - Ability to coach junior staff and contractors TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives.
Our platform connects people from across the globe and so does our workplace.
At TikTok, our mission is to inspire creativity and bring joy.
To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach.
We are passionate about this and hope you are too.
TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws.
If you need assistance or a reasonable accommodation, please reach out to us at https:
//shorturl.
at/cdpT2RegularExperienced.
Estimated Salary: $20 to $28 per hour based on qualifications.

Don't Be a Victim of Fraud

  • Electronic Scams
  • Home-based jobs
  • Fake Rentals
  • Bad Buyers
  • Non-Existent Merchandise
  • Secondhand Items
  • More...

Don't Be Fooled

The fraudster will send a check to the victim who has accepted a job. The check can be for multiple reasons such as signing bonus, supplies, etc. The victim will be instructed to deposit the check and use the money for any of these reasons and then instructed to send the remaining funds to the fraudster. The check will bounce and the victim is left responsible.