Bug Bounty Security Researcher

Jobgether

Portugal

Presencial

EUR 60 000 - 90 000

Tempo integral

Há 7 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura completa num minuto — currículo e carta de apresentação personalizados, prontos a enviar.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Flexible freelance engagement
Weekly payments
Bounty rewards
Leaderboard recognition
Private bug bounty programs

Resumo da oferta

Jobgether, listing on behalf of a partner company, seeks a Bug Bounty Security Researcher based in Portugal. You’ll investigate applications, systems, and networks to uncover security weaknesses before exploitation.

Work spans web, mobile, and network security across private and public bug bounty programs. You will validate vulnerabilities, produce detailed reports, and contribute to improving products and vulnerability management practices, with continuous learning and high-impact discoveries

Qualificações

  • 1+ year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or related field.
  • Strong understanding of computer systems, networks, web apps and software security.
  • Experience with offensive security methodologies and vulnerability discovery techniques.
  • Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
  • Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, Kali Linux.
  • Experience in bug bounty programs and responsible disclosure.
  • Strong analytical, investigative and problem-solving abilities.
  • Excellent technical communication and documentation skills.

Responsabilidades

  • Conduct security research across target applications, systems and networks to identify vulnerabilities and attack paths.
  • Develop and execute customized attack vectors using fuzzing, SQLi, XSS, SSRF, and RCE.

Conhecimentos

Python
C++
JavaScript
HTML
Burp Suite
OWASP ZAP
Nmap
Kali Linux
Bug bounty
Responsible disclosure
CVEs
BSCP/OSWE/GWAPT/OSCP
Public bug bounty profile

Ferramentas

Burp Suite
OWASP ZAP
Nmap
Kali Linux

Descrição da oferta de emprego

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Bug Bounty Security Researcher based in Portugal.

This is an exciting security research opportunity for a skilled professional passionate about discovering vulnerabilities and strengthening real-world application security.
You will investigate software applications, systems, and networks to uncover security weaknesses before they can be exploited maliciously.
The role combines offensive security research, creative attack development, vulnerability exploitation, and detailed technical reporting.
You will work across web, mobile, and network security environments while participating in private and public bug bounty programs.
Your findings will directly contribute to improving security products and services and protecting customers against emerging threats.
The position offers flexibility to work independently, explore challenging targets, and be rewarded for high-impact vulnerabilities.
This opportunity is ideal for a curious and analytical security researcher who enjoys continuous learning and responsible vulnerability disclosure.

Accountabilities
  • Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.
  • Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.
  • Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.
  • Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.
  • Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.
  • Participate in ongoing bug bounty programs and private security research engagements.
  • Share security findings and insights that can help improve products, services, and overall vulnerability management practices.
  • Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.
  • Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.
Requirements
  • At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.
  • Strong understanding of computer systems, networks, web applications, and software security.
  • Practical knowledge of offensive security methodologies and vulnerability discovery techniques.
  • Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
  • Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.
  • Experience participating in bug bounty programs and applying responsible disclosure practices.
  • Strong analytical, investigative, and problem-solving abilities.
  • Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.
  • Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.
  • 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.
  • A recognized public bug bounty profile with awarded vulnerability reports is preferred.
  • Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.
  • Strong sense of responsibility and commitment to ethical security research.
Benefits
  • Flexible freelance engagement allowing you to work according to your own schedule.
  • Bounty awards for valid and accepted vulnerability reports.
  • Weekly payments for valid reports following successful triage.
  • Recognition for high-quality submissions through leaderboards both on and outside the platform.
  • Opportunities to perform real-world penetration testing across web application, mobile, and network security.
  • Access to private and exclusive bug bounty programs.
  • Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.
  • Collaborative, empathy-led security culture focused on improving internet security.
  • Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Freelance Bug Bounty Security Researcher
Freelance Bug Bounty Security Researcher

Jobgether • Portugal

Presencial
EUR 60 000 - 90 000
Flexible freelance engagement
Weekly payments
Bounty rewards
+2
Offensive Security Specialist
Offensive Security Specialist

Claranet • Porto

Híbrido
EUR 55 000 - 75 000
Certification resources
Team building
Friendly workplace
Application Security
Application Security

WIREIT • Portugal

Híbrido
EUR 40 000 - 60 000
Health Insurance
22 days of paid vacation
4 extra vacation days
+5
Application Security
Application Security

WIRE IT • Porto

Híbrido
EUR 40 000 - 60 000
Health Insurance
22 days of paid vacation
4 extra days annually (Carnival, Christmas Eve, New Year's Eve, Birthday)
+6
Offensive Security Specialist
Offensive Security Specialist

Jobbex IT • Porto

Presencial
EUR 55 000 - 85 000
Application Security (Appsec) Engineer
Application Security (Appsec) Engineer

Uncover • Lisboa

Híbrido
EUR 60 000 - 90 000
Flexible hours
Remote work 52 days/yr
22 days paid annual leave
+1
Offensive Security Manager (Penetration Testing | Red Team | Adversary Simulation)
Offensive Security Manager (Penetration Testing | Red Team | Adversary Simulation)

Thales • Maia

Presencial
EUR 70 000 - 90 000
Competitive compensation package
Continuous learning environment
Flexible working model
Application Security Engineer
Application Security Engineer

Joom • Lisboa

Híbrido
EUR 48 000 - 72 000
Horário flexível
Opção de trabalho remoto
Seguro de saúde (inclui dependentes)
+2
VULNERABILITY MANAGEMENT SPECIALIST (HYBRID)
VULNERABILITY MANAGEMENT SPECIALIST (HYBRID)

iTRTech Group • Lisboa

Híbrido
EUR 40 000 - 44 000
Offensive Security Specialist M/F – Hybrid (Porto)
Offensive Security Specialist M/F – Hybrid (Porto)

SysMatch • Porto

Híbrido
EUR 40 000 - 50 000
Competitive salary
Hybrid work model
Career development opportunities
+1