Security Triage Analyst

Verda

Greater London

Hybrid

GBP 70,000 - 90,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Verda in London is seeking a Security Triage Analyst to own the first layer of judgement on every vulnerability report. You will validate findings, reproduce safely, assess impact, and write clear outcomes for engineers. The environment includes multi-tenant GPU infrastructure and cloud services.

You will work with Security, Engineering, and external researchers to shape triage processes, handle sensitive material, and ensure fast, accurate triage in a growing global cloud platform.

Qualifications

  • 5+ years of experience in vulnerability triage, application security, or related security roles
  • Ability to understand and validate technical vulnerability reports
  • Practical knowledge of web app and API security concepts
  • Infrastructure and cloud security depth for multi-tenant environments
  • Ability to reproduce findings safely using common tools
  • Sound judgement on severity and impact using CVSS or similar models
  • Strong attention to detail when reviewing evidence and reproduction steps
  • Professional handling of external researchers and reports
  • Curiosity to learn in environments without a runbook

Responsibilities

  • Review incoming reports from researchers, bug bounty programs, tests, and internal assessments
  • Validate findings, reproduce when safe, and confirm realistic impact in Verda's environment
  • Classify findings and provide clear, defensible decisions
  • Assess severity and impact using CVSS alongside multi-tenant context
  • Collaborate with security engineers to separate real bugs from expected behavior
  • Communicate with researchers professionally and seek clarifications
  • Turn valid findings into actionable internal tickets for engineering
  • Keep the queue moving and link duplicates clearly
  • Improve triage templates, guidance, and workflows as volume grows
  • Handle sensitive material carefully including credentials, logs, and exploit chains

Tools

Burp Suite
Curl
Browser dev tools
API clients
Scripting

Job description

At Verda, we're building a full-stack AI cloud, covering everything from data centers and hardware to our own cloud platform that the world's leading AI teams use to do serious AI work.

We strive to make a positive mark on the world through the infrastructure we build and give leading teams a service they can truly depend on. Headquartered in Helsinki, we operate globally with offices in London and San Francisco.

Join Verda while it’s still being built - not once it’s finished.

Why Verda
  • Cash and equity compensation along with various fringe benefits.

  • Profitable operations with rapid, sustained growth.

  • 40+ nationalities, with 6 different ones on the management team.

  • A real chance to make an impact and work alongside world class engineers, researchers, and partners across the global AI ecosystem.

About the role

Vulnerability triage is often treated as queue work: read the report, check the scope, set a severity, move it on. We are building this role differently. As Security Triage Analyst you own the first layer of judgement on every report that reaches Verda – what is real, what matters, what needs more evidence, and what happens next – reproducing findings where it is safe to, assessing impact, and writing them up so engineers can act.

The environment is unusual: Verda runs multi-tenant GPU infrastructure, customer-facing cloud services, APIs, and management planes, so a report that looks routine elsewhere can matter more here because of tenant isolation, customer impact, or infrastructure access.

You will work closely with Security, Engineering, Infrastructure, external triage partners, and researchers, and you will help improve how vulnerability handling works as the volume grows.

Your responsibilities
  • Review incoming reports from external researchers, bug bounty and vulnerability disclosure programmes, penetration tests, AI-assisted testing platforms, and internal security assessments

  • Validate findings: check the affected asset, reproduce the issue where safe and appropriate, and confirm whether the described impact is realistic in Verda's environment

  • Classify findings as valid vulnerability, duplicate, false positive, expected behaviour, accepted risk, out of scope, or needs more information, and make each decision understandable and defensible

  • Assess severity and impact using CVSS (Common Vulnerability Scoring System) alongside Verda's own context: multi-tenancy, customer data, infrastructure access, and privilege boundaries

  • Work with the offensive security team and security engineers to separate real bugs from expected product behaviour, standard cloud configuration, intentionally public assets, and findings outside Verda's threat model

  • Communicate with researchers, external triage teams, and vendors professionally, including asking for clarification, explaining decisions, and handling appeals

  • Turn valid findings into internal tickets engineering teams can act on: what is affected, how it was reproduced, the impact, the evidence, and the expected next step

  • Keep the queue moving so high and critical reports surface quickly, duplicates are linked cleanly, and unclear reports always have a clear next action

  • Improve how we run the programme as volume grows – report templates, researcher guidance, severity rules, duplication logic, workflows, and metrics on volume, time to triage, and time to resolution – treating duplicates and false positives as signal about where it needs work

  • Handle sensitive material carefully, since reports can contain customer-impacting detail, internal infrastructure information, credentials, screenshots, logs, and exploit chains

Your key competencies
  • 5+ years of previous experience in vulnerability triage, application security, penetration testing, security operations, or a closely related security role

  • Ability to understand and validate technical vulnerability reports, including incomplete, unclear, automated, or poorly written ones

  • Practical knowledge of web application and API security: authentication, authorisation, access control, CORS (Cross-Origin Resource Sharing), rate limiting, SSRF (Server-Side Request Forgery), injection issues, file handling, and business logic flaws

  • Enough infrastructure and cloud security depth to reason about network exposure, internal services, storage, identity, Kubernetes, management interfaces, and multi-tenant environments

  • Ability to reproduce findings safely using tools such as Burp Suite, curl, browser developer tools, API clients, logs, and basic scripting

  • Sound judgement on severity and impact using CVSS or a comparable model – telling the finding that matters from the one that only looks serious at first glance

  • Strong attention to detail when comparing duplicates, checking evidence, and reviewing reproduction steps

  • Professional handling of external researchers, including unclear, automated, duplicated, disputed, or appealed reports

  • Comfortable where there is no runbook yet, with the curiosity to learn an environment most security people have not seen

Nice to have
  • Experience managing or operating a bug bounty or vulnerability disclosure platform such as YesWeHack, HackerOne, or Bugcrowd, including researcher reward models and severity appeals

  • Background in cloud service providers, hosting, infrastructure, or multi-tenant platforms

  • Familiarity with Kubernetes, object storage, IAM (Identity and Access Management), VPNs (Virtual Private Networks), APIs, and customer-facing cloud consoles

  • Basic Python, Bash, or other scripting for reproducing issues and automating repetitive triage tasks

  • Experience with AI-assisted security testing, or reviewing AI-generated vulnerability reports

  • Relevant certifications

Practicalities
  • Location: London, UK

  • Hybrid mode: Working 3 days a week from our London office

  • Employment type: Full time and permanent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Kubernetes and Container Platform Security Specialist
Kubernetes and Container Platform Security Specialist

Verda • Greater London

Hybrid
GBP 120,000 - 180,000
Cash and equity compensation
Fringe benefits
Platform Engineer - LLM Inference Infrastructure
Platform Engineer - LLM Inference Infrastructure

Verda • Greater London

On-site
GBP 110,000 - 140,000
Cash & equity
Healthcare
Lunch
+2
Office Operations Specialist (UK)
Office Operations Specialist (UK)

Verda • Greater London

On-site
GBP 32,000 - 48,000
Equity and cash compensation
Healthcare
Wellbeing benefits
Head of IT
Head of IT

Verda • Greater London

Hybrid
GBP 150,000 - 190,000
Senior Product Marketing Manager - Platform and Developer
Senior Product Marketing Manager - Platform and Developer

Verda • Greater London

On-site
GBP 90,000 - 130,000
Equity compensation
Healthcare
Lunch
+2
Vulnerability Management Analyst
Vulnerability Management Analyst

Inspired Thinking Group (ITG) • Birmingham

On-site
GBP 55,000 - 75,000
Time off and wellbeing days
Enhanced family-friendly leave
Pension scheme
+2
IT Procurement Specialist
IT Procurement Specialist

Verda • Greater London

Hybrid
GBP 50,000 - 75,000
Cash and equity
Fringe benefits
Global team
Junior Growth Sales Representative
Junior Growth Sales Representative

Verda • Greater London

Hybrid
GBP 40,000 - 60,000
Cash and equity compensation
Healthcare
Wellbeing and more
Vulnerability Manager
Vulnerability Manager

The Very Group • Liverpool

On-site
GBP 60,000 - 80,000
Flexible working model
30 days holiday + bank holidays
£1000 flexible benefits allowance
+2
Cyber Security Manager
Cyber Security Manager

Applied Computing • City Of London

On-site
GBP 70,000 - 100,000