- Company Name
- Intigriti
- Job Title
- Product Security Analyst
- Job Description
-
**Job Title:** Product Security Analyst
**Role Summary:**
Analyze and triage product‑level security vulnerability reports from a global researcher community. Conduct research, proof‑of‑concept (POC) validation, severity assessment and CVSS scoring across diverse product families (software libraries, firmware, embedded systems, operating systems, etc.). Engage with researchers and client security teams to provide actionable remediation guidance and foster continuous improvement in vulnerability reporting quality.
**Expectations:**
- Handle incoming vulnerability reports, ensuring uniqueness, clarity, and business impact relevance.
- Deliver timely, high‑quality feedback to researchers and clients.
- Actively contribute to a 24/7 support environment with flexible working hours.
- Maintain up‑to‑date knowledge of emerging threats, malware, and attack techniques.
**Key Responsibilities:**
- Review, validate, and title vulnerability reports received via the platform.
- Perform POCs, security testing, and influence severity rating with CVSS calculations.
- Communicate findings, remediation steps, and business impact to security teams and clients.
- Motivate and mentor vulnerability researchers to improve detection and reporting.
- Collaborate with success management to build strong client and community relationships.
- Conduct penetration tests and security validation on libraries, firmware/hardware, embedded systems, and networks.
- Proactively identify systemic issues and provide strategic improvement recommendations.
- Document processes, findings, and lessons learned for internal and client use.
**Required Skills:**
- Excellent written and verbal communication in English.
- Strong interpersonal skills, service‑oriented mindset.
- Hands‑on experience in pentesting, vulnerability assessment, and security testing.
- Deep understanding of ethical hacker culture and security research practices.
- Analytical, detail‑oriented, and problem‑solving ability with resourceful research skills.
- Ability to calculate CVSS scores and assess business impact.
- Comfortable with 24/7 support shifts and flexible work hours.
- Knowledge of at least four of: web/mobile application security, network security, embedded systems/FPGAs, binary exploitation, game hacking, SIEM/SOAR, OS/driver hacking.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent combination of education and 3 years of experience.
- Preferred certifications: OSCP, OSWE, eJPT, CEPT, CPTS, or other relevant credential.
- Personal bug‑bounty or security research profile is a plus.