Senior Security Analyst - Bug Bounty
Senior Security Analyst - Bug Bounty

Senior Security Analyst - Bug Bounty

Cheltenham Full-Time 43200 - 72000 £ / year (est.) Home office possible
N

At a Glance

  • Tasks: Analyse security findings and communicate with researchers to enhance security measures.
  • Company: NCC Group is a leader in cyber security, dedicated to creating a secure digital future.
  • Benefits: Enjoy flexible working, wellness programs, and a comprehensive benefits package.
  • Why this job: Engage with top ethical hackers and contribute to global security for major companies.
  • Qualifications: Strong experience in security analysis, programming, and vulnerability management required.
  • Other info: Remote work available; must pass pre-employment background checks.

The predicted salary is between 43200 - 72000 £ per year.

Location: Remote (UK or Spain)

Role Purpose:

  • Analyse and fully reproduce potential security findings reported to our clients.
  • Communicate with the global researcher community to gather information and inform them triage analysis outcomes.
  • Author and deliver NCC-quality vulnerability reports to the specifications of individual clients.
  • Drive or contribute to projects that improve BBS’ tooling, operational processes, and delivery quality.
  • Provide mentorship and technical guidance to associate security analysts, fostering their professional development and enhancing their technical skills.

Summary:

Due to continued growth, NCC Group is seeking an experienced and seasoned Bug Bounty Triager to join the Bug Bounty Services (BBS) Practice as a Senior Security Analyst on our Tier 1 Triage Team. As the premiere triage team in the bug bounty domain, the team’s Security Analysts have the unique opportunity to directly engage with the security researcher community on their findings on behalf of our Enterprise clients. The Tier 1 Triage team is fully distributed in NA, EMEA, and APAC, and this role directly reports to BBS’ Spain-based Director of Triage.

What we are looking for in you:

  • Native speaker or CEFRL C2 English language proficiency.
  • Excellent written and verbal communication skills.
  • Strong experience in web application, network, and mobile application security, with hands-on experience identifying and remediating vulnerabilities in real-world applications.
  • Proven experience in application security source code reviews.
  • Professional experience that required regular use of programming scripting languages.
  • Vulnerability Disclosure and Bug Bounty experience.
  • Experience with SAST and DAST testing tools.
  • Vulnerability Management experience.
  • Software QA experience is a plus.

Behaviours:

  • Focusing on Clients and Customers.
  • Working as One NCC.
  • Always Learning.
  • Being Inclusive and Respectful.
  • Delivery Brilliantly.

Why NCC Group?

At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people-powered business seeking the next group of brilliant minds to join our ranks.

Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as opportunities for learning and development and career growth. We believe our people are at their brilliant best when they feel bolstered in all aspects of their well-being, and we offer wellness programs and flexible working arrangements to provide that vital support.

Are you ready to triage security vulnerabilities reported by some of the world's top ethical hackers for the most prominent global companies? Come join us!

What do we offer in return?

  • We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits.
  • Flexible working
  • Financial & Investment
  • Pension
  • Life Assurance
  • Share Save Scheme
  • Maternity & Paternity leave
  • Community & Volunteering Programmes
  • Cycle Scheme
  • Office Lifestyle
  • Employee Referral Program
  • Lifestyle & Wellness
  • Learning & Development
  • Diversity & Inclusion

So, what’s next?

If this sounds like the right opportunity for you, then we would love to hear from you! Click on apply to this job to send us your CV and the relevant member of our global talent team will be in touch with you. Alternatively send your details to global.ta@nccgroup.com.

About your application

We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles. If you do not want us to retain your details, please email global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Policy. We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.

Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process. This role being advertised will be subject to BS7858 screening as a mandatory requirement.

Senior Security Analyst - Bug Bounty employer: NCC Group

NCC Group is an exceptional employer that prioritises the well-being and professional growth of its employees, offering a flexible remote working environment in the UK or Spain. With a strong commitment to inclusivity and collaboration, employees benefit from comprehensive wellness programmes, learning opportunities, and a culture that values creativity and accountability. Join us to engage with top ethical hackers and contribute to securing a more digital future while enjoying a balanced work-life experience.
N

Contact Detail:

NCC Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Security Analyst - Bug Bounty

✨Tip Number 1

Familiarise yourself with the latest trends in web application and mobile security. Being up-to-date with current vulnerabilities and exploits will not only help you in interviews but also demonstrate your passion for the field.

✨Tip Number 2

Engage with the bug bounty community on platforms like HackerOne or Bugcrowd. Building connections and participating in discussions can provide insights into what companies are looking for and may even lead to referrals.

✨Tip Number 3

Prepare to discuss your experience with SAST and DAST tools in detail. Be ready to share specific examples of how you've used these tools to identify and remediate vulnerabilities in past projects.

✨Tip Number 4

Showcase your mentorship skills by discussing any previous experiences where you've guided junior analysts or peers. Highlighting your ability to foster professional development can set you apart from other candidates.

We think you need these skills to ace Senior Security Analyst - Bug Bounty

Native English speaker or CEFRL C2 proficiency
Excellent written and verbal communication skills
Strong experience in web application security
Network security expertise
Mobile application security knowledge
Hands-on experience identifying vulnerabilities
Experience in application security source code reviews
Proficiency in programming and scripting languages
Vulnerability Disclosure experience
Bug Bounty programme experience
Familiarity with SAST and DAST testing tools
Vulnerability Management experience
Software QA experience (desirable)
Ability to mentor and provide technical guidance
Project management skills
Adaptability and willingness to learn

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in web application, network, and mobile application security. Emphasise your hands-on experience with identifying and remediating vulnerabilities, as well as any programming or scripting languages you are proficient in.

Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and the bug bounty domain. Mention specific experiences that align with the role's requirements, such as your vulnerability management experience and any previous work with SAST and DAST testing tools.

Showcase Communication Skills: Since excellent written and verbal communication skills are crucial for this role, ensure your application materials are clear, concise, and free of errors. Consider including examples of how you've effectively communicated technical information to non-technical stakeholders.

Highlight Mentorship Experience: If you have experience mentoring or providing technical guidance to others, be sure to include this in your application. This aligns with the role's requirement to foster professional development among associate security analysts.

How to prepare for a job interview at NCC Group

✨Showcase Your Technical Skills

Be prepared to discuss your hands-on experience with web application, network, and mobile application security. Highlight specific vulnerabilities you've identified and remediated in real-world applications, as this will demonstrate your practical knowledge.

✨Communicate Clearly

Since excellent written and verbal communication skills are crucial for this role, practice articulating your thoughts clearly. You might be asked to explain complex security concepts, so ensure you can do this in a way that's easy to understand.

✨Familiarise Yourself with Bug Bounty Processes

Understand the bug bounty landscape and be ready to discuss your experience with vulnerability disclosure and bug bounty programmes. This shows that you're not only technically proficient but also aware of the community and its practices.

✨Demonstrate Mentorship Experience

As the role involves providing mentorship to associate security analysts, be prepared to share examples of how you've guided others in the past. This could include training sessions, code reviews, or any other form of support you've provided.

Senior Security Analyst - Bug Bounty
NCC Group
N
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>