Ovii Job Board

Product Security Analyst

hackerone

Washington, United States • Remote - Washington, United States • Full-Time • 3+ years

Posted 2026-08-04 USD 120,000 - USD 155,000 per year Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

The Product Security Analyst joins HackerOne’s Technical Services team to evaluate, reproduce, and communicate vulnerability findings for web and mobile applications. Working remotely within select U.S. hubs, you’ll apply security frameworks, automation, and AI‑enabled workflows to ensure high‑quality customer experiences.

Role Snapshot

  • Vulnerability triage
  • Web & mobile app security
  • Customer‑facing communication
  • AI‑driven workflow automation
  • Remote collaboration across US hubs

Must-Have Requirements

  • Web application security
  • Mobile application security
  • OWASP Top 10 knowledge
  • CVSS scoring
  • Burp Suite
  • Excellent written and verbal communication in English
  • Weekend shift availability
  • US work authorization
  • security testing
  • vulnerability research
  • web and mobile application security
  • Visa/work permit sponsorship is not available
  • Background check required

Nice-to-Have Signals

  • Bug bounty or vulnerability disclosure program experience
  • Scripting or automation for security testing
  • Ability to manage competing priorities in fast‑paced environment
  • bug bounty participation
  • security testing automation

Work Setup

  • Location: Washington, United States
  • Work mode: REMOTE
  • Remote scope: COUNTRY_RESTRICTED
  • Remote countries: United States
  • Employment type: Full-Time
  • Shift: Weekend shifts may be required

Eligibility Gates

  • Work authorization: Must be authorized to work in the United States
  • Visa sponsorship: no
  • Background check: required

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility details

What You'll Likely Work On

  • Evaluate vulnerability reports, determine severity and business impact using CVSS and other security frameworks.
  • Reproduce reported web and mobile vulnerabilities, identify root causes, and communicate impact clearly.
  • Collaborate with external security researchers to gather details, improve report quality, and maintain professional customer communication.
  • Create concise technical summaries with reproduction steps, impact analysis, and remediation guidance.
  • Adapt to evolving customer environments, emerging attack techniques, and shifting program scopes.
  • Leverage automation and AI‑enabled workflows to improve triage efficiency and analysis quality.
  • Partner with Technical Services and customer‑facing teams to ensure timely handling and a high‑quality experience.
  • Identify and implement process, documentation, and tooling improvements for scalability and consistency.
  • Participate in occasional weekend shifts as needed.

Good Fit If You Have

  • Enjoys hands‑on vulnerability reproduction and root‑cause analysis.
  • Clear communicator for both technical and non‑technical audiences.
  • Thrives in fast‑paced, globally distributed environments.
  • Willing to work occasional weekend shifts.

Skills

  • OWASP Top 10 knowledge
  • CVSS scoring
  • Burp Suite
  • Web application security
  • Mobile application security
  • Technical writing (English)
  • Automation scripting (preferred)
  • Bug bounty program experience (preferred)

Remote Eligibility

  • United States
  • Washington DC
  • Seattle
  • San Francisco Bay Area
  • Boston
  • Austin