
Product Security Analyst
hackerone
Posted 2026-08-04
USD 120,000 - USD 155,000 per year
Tech & Engg
Job Description
Ovii's Interpretation of the Role
The Product Security Analyst joins HackerOne’s Technical Services team to evaluate, reproduce, and communicate vulnerability findings for web and mobile applications. The role blends hands‑on security testing with AI‑enabled triage and close collaboration with researchers and customers.
Role Snapshot
- Security testing of web & mobile apps
- Vulnerability validation & reproduction
- Customer‑researcher communication
- AI‑assisted triage workflows
- Remote work (US‑only) with occasional weekend shifts
Must-Have Requirements
- Web & mobile application security testing
- OWASP Top 10 knowledge
- Burp Suite
- CVSS familiarity
- English written & verbal communication
- security testing
- web and mobile application security
- Visa sponsorship not available
- Must be authorized to work in the United States
Nice-to-Have Signals
- Bug bounty or vulnerability disclosure program participation
- Scripting or automation for security testing
- Managing competing priorities in fast‑paced environment
- bug bounty program participation
- scripting/automation experience
Work Setup
- Location: Washington, United States
- Work mode: REMOTE
- Remote scope: COUNTRY_RESTRICTED
- Remote countries: United States
- Travel: Weekend shifts may be required
- Employment type: Full-Time
- Shift: Weekend shifts may be required
Eligibility Gates
- Work authorization: Must be authorized to work in the United States
- Visa sponsorship: no
- Background check: Contingent on background check
Not Specified in JD
- Visa sponsorship
- Education requirement
What You'll Likely Work On
- Assess vulnerability reports using CVSS and data‑driven decision making
- Reproduce and validate web and mobile vulnerabilities independently
- Collaborate with researchers to clarify details and improve report quality
- Draft concise technical summaries with remediation guidance
- Leverage automation and AI‑enabled tools to streamline triage
- Partner with Technical Services and customer‑facing teams for timely resolution
- Identify and implement process, documentation, and tooling improvements
- Participate in occasional weekend shifts as needed
Good Fit If You Have
- Enjoys translating complex technical findings into clear customer communications
- Thrives in a globally distributed, fast‑moving environment
- Has a proactive mindset for improving security workflows
Skills
- Web & mobile application security testing
- OWASP Top 10 knowledge
- Burp Suite
- CVSS scoring
- English written & verbal communication
- Bug bounty program experience (preferred)
- Scripting/automation for security testing (preferred)
- Prioritization in fast‑paced environments (preferred)
Remote Eligibility
- United States
- Washington DC
- Seattle
- San Francisco Bay Area
- Boston
- Austin