Bug Bounty Analyst

tsys

Leicester

On-site

GBP 60,000 - 80,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Global Payments is seeking an experienced Bug Bounty Analyst to join our Security Operations team. You will manage assessment, coordination and remediation of findings from our Bug Bounty Program, supporting triage and ensuring timely reporting to remediation owners while overseeing retests.

Work closely with business lines, security champions, and legal teams to mature the program, document risks, and keep runbooks up to date.

Qualifications

  • Bachelor's degree in Computer Science, Info Security, or related field.
  • Typically 2+ years of vulnerability management or bug bounty program experience.
  • Knowledge of Unix/Linux/macOS/Windows and security operations, IDS, SIEM, pentesting, secure coding.

Responsibilities

  • Assess vulnerabilities and assign severity per CVSS.
  • Communicate findings to technical and non-technical stakeholders.
  • Develop remediation strategies with timelines.
  • Coordinate remediation with white-hat researchers.
  • Analyze findings for visibility gaps and fix monitoring gaps.
  • Identify missing security controls and ensure tracking to completion.
  • Mature the program by onboarding new assets.
  • Collaborate with Risk Management to document risks and issues.
  • Maintain knowledge of PCI, HIPAA, GDPR, PII, NIST CSF.
  • Work with Legal and Privacy Offices when data is at risk.
  • Maintain runbooks for day-to-day activities.

Skills

Vulnerability management
Bug bounty
Communication skills
Stakeholder comms
Threat assessment

Education

Bachelor's degree in Computer Science or related

Tools

ServiceNow
JIRA
Vulnerability scanners

Job description

Every day, Global Payments makes it possible for millions of people to move money between buyers and sellers using our payments solutions for credit, debit, prepaid and merchant services. Our worldwide team helps over 3 million companies, more than 1,300 financial institutions and over 600 million cardholders grow with confidence and achieve amazing results. We are driven by our passion for success and we are proud to deliver best-in-class payment technology and software solutions. Join our dynamic team and make your mark on the payments technology landscape of tomorrow.

Ready to take your career global?

Make your mark at one of the biggest names in payments. We're looking for an experienced Bug Bounty Analyst to join our ever evolving team and help shape the future of global commerce.

About the Role

This role is an opportunity to work in an exciting, fast paced and complex industry in our Security Operations organization, and will play a vital role in the day to day management of our Bug Bounty Program.

As part of the Bug Bounty Coordination team you will be responsible for the assessment, coordination and remediation of findings reported through our Bug Bounty Program from hackers that participate in our programs. You will support ticket triage and ensure findings are reported to remediation owners in a timely manner while overseeing remediation efforts and retest. You will work closely with various lines of business and security champions across the organization to also mature the program and help secure Global Payments assets.

What You’ll Own
  • Assess and support severity assignment on reported vulnerabilities/bugs in line with the Common Vulnerability Scoring System (CVSS)
  • Effectively communicating vulnerability findings to stakeholders, including technical and non-technical audiences
  • Developing strategies to address identified vulnerabilities, including mitigation plans and timelines
  • Coordinate the remediation of findings from the organisation's Bug Bounty & Vulnerability Disclosure Programs working directly with whitehat researchers
  • Analyze findings to understand if our vulnerability scanners failed to identify them and work with the relevant to address any visibility gaps
  • Identify missing security controls that could have mitigated the Bug Bounty finding and ensure correction is tracked to completion
  • Mature the program through the onboarding of new assets
  • Works closely with Risk Management teams to document identified risks and issues highlighted through Bug Bounty Program
  • Maintains a working knowledge of key data security frameworks and regulations such as PCI (Payment Card Industry)/Logical Security guidelines and models, HIPPA (Health Insurance Portability and Accountability Act), (GDPR) General Data Protection Regulation, PII (Personally Identifiable Information), NIST CSF (Cyber Security Framework).
  • Collaborates with Legal and Privacy Offices when critical data is at risk as a result of a Bug Bounty finding
  • Maintain and follow runbooks for day-to-day activities
What You’ll Bring
  • Relevant Experience or Degree in: Bachelor's degree in Computer Science, Info Security, or related field. Or relevant work experience in a related field.
  • Typically Minimum 2 Years Relevant Experience with Vulnerability Management or involved in Bug Bounty Program handling
  • Knowledge of network operations or engineering or system administration on Unix, Linux, MAC (Message Authentication Code), or Windows; common security operations, intrusion detection systems, Security Incident Event Management systems, Penetration Testing, Web Application assessment, Secure Coding practices, Cloud Technologies.
Preferred Qualifications
  • Professional security certifications such as CompTIA Security+ or CompTIA PenTest, Systems Security Certified Practitioner (SSCP), or CISM(Certified Information Security Manager), or CISA(Certified-Information-Systems-Auditor) or CEH (Certified Ethical Hacker)
  • Certified Secure Software Lifecycle Professional (CCSLP) or GIAC Web Application Defender (GWEB) or eJPT (eLearnSecurity Junior Penetration Tester), OSCP (Offensive Security Certified Professional)
  • Knowledge of industry standard security compliance programs PCI (Payment Card Industry), GDPR (General Data Protection Regulation), NIST Cyber Security Framework etc.
  • Experience working with ticketing systems such as ServiceNow and/or JIRA
What Are Our Desired Skills and Capabilities?
  • Strong verbal and written communication skills.
  • Attention to detail - reads and actively listens with an eye for detail.
  • Demonstrated ability to effectively communicate ideas and persuade others to accomplish challenging goals and objectives.
  • Ability to facilitate meetings and enable discussions that lead to resolution and communicate results.
  • Vulnerability Management - knowledge with a proven record of assessing application and infrastructure vulnerabilities; understanding exploit methodologies.

Skills / Knowledge - Developing professional expert

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Bug Bounty Analyst
Bug Bounty Analyst

Global Payments Inc. • Greater London

On-site
GBP 60,000 - 90,000
Bug Bounty Analyst
Bug Bounty Analyst

Global Payments Inc. • Leicester

On-site
GBP 65,000 - 90,000
Bug Bounty Analyst
Bug Bounty Analyst

Global Payments • Leicester

On-site
GBP 50,000 - 70,000
Bug Bounty Security Analyst
Bug Bounty Security Analyst

Global Payments Inc. • Greater London

On-site
GBP 60,000 - 90,000
Bug Bounty Program Lead
Bug Bounty Program Lead

Global Payments Inc. • Leicester

On-site
GBP 65,000 - 90,000
Bug Bounty Program Lead
Bug Bounty Program Lead

tsys • Leicester

On-site
GBP 60,000 - 80,000
Bug Bounty Program Specialist
Bug Bounty Program Specialist

Global Payments • Leicester

On-site
GBP 50,000 - 70,000
Vulnerability Management Analyst
Vulnerability Management Analyst

Inspired Thinking Group • Birmingham

On-site
GBP 52,000 - 86,000
Work from home
25 Days Holidays + Bank Holidays
Wellbeing program
+2
Security Analyst
Security Analyst

NCC Group • Greater Manchester

On-site
GBP 52,000 - 78,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Director, Issues Management
Director, Issues Management

Global Payments Inc. • Greater London

On-site
GBP 120,000 - 190,000