About the position
Envoy is seeking exceptional engineers to join their team and drive innovation in the workplace. The role involves triaging and prioritizing vulnerability reports, collaborating with development teams, deploying and managing automated security scanners, conducting code audits, and managing the bug bounty program. The ideal candidate should have expertise in vulnerability triaging, experience with automated security scanners, knowledge of secure coding practices, and the ability to effectively communicate and coordinate with security researchers. Strong analytical and problem-solving skills are also required.
Responsibilities
- Triage and prioritize incoming vulnerability reports from various sources
- Collaborate with development teams to reproduce and validate reported vulnerabilities
- Coordinate with internal stakeholders to implement necessary remediation actions and track their progress
- Deploy and manage automated security scanners, including SAST, DAST, and SCA tools
- Conduct code audits and reviews to identify security vulnerabilities, coding best practices violations, and architectural weaknesses
- Manage and maintain the bug bounty program, including program guidelines, scope definition, and engagement with security researchers
- Stay up to date with the latest security trends, emerging vulnerabilities, and industry best practices to continuously improve security measures
Requirements
- Demonstrated expertise in triaging and prioritizing vulnerability reports
- Proficient in reproducing reported vulnerabilities and working closely with development teams
- Strong hands-on experience with deploying and managing automated security scanners
- Knowledge of industry-leading security scanning tools and their integration into development pipelines
- In-depth understanding of secure coding practices and ability to perform code audits
- Proficiency in programming languages commonly used in web and application development
- Proven track record in managing successful bug bounty programs
- Ability to effectively communicate and coordinate with security researchers
- Strong analytical and problem-solving skills
- Excellent troubleshooting and problem-solving abilities in complex technical environments
Benefits
- A high degree of trust in your ideas and execution
- An opportunity to partner and collaborate with other talented people
- An inclusive community where you feel welcomed and cared for as a person
- The ability to make an immediate impact helping customers create a great workplace experience
- Support for your personal and professional growth
- Market competitive salary
- Equity for all full-time roles
- Great benefits package
- Expected cash compensation of $200k (annually) for roles located in the San Francisco Bay Area
- Multiple levels and backgrounds for hiring, with final offers varying based on experience, expertise, and other factors
- Privacy notice for applicants provided
- Equal Employment Opportunity (EEO) Employer