Ethical Hacker
Summary
Triages and validates bug bounty submissions and performs web application/API penetration tests for HACKRATE's customers: reproducing and severity-rating vulnerabilities, writing reports, and communicating with researchers and clients. Core tech: OWASP methodology, web/API security testing.
- Managing the day-to-day technical operation of customers' bug bounty programs
- Reviewing vulnerability reports submitted by ethical hackers
- Reproducing and validating reported vulnerabilities
- Identifying valid findings, duplicates, invalid reports and known issues
- Assessing severity and real technical impact
- Requesting additional information from researchers when necessary
- Communicating with ethical hackers about their reports
- Supporting customers with technical questions related to reported vulnerabilities
- Escalating complex cases to the Head of Ethical Hacking Services
- Helping ensure consistent vulnerability handling across programs
- Performing penetration tests primarily on web applications and APIs
- Independently managing smaller and less complex penetration testing projects from preparation through testing and reporting
- Reviewing the scope, testing environment, documentation and test accounts before starting an assessment
- Assessing the technical impact and severity of findings
- Writing clear vulnerability descriptions, reproduction steps and remediation recommendations
- Preparing professional penetration testing reports
- Performing retesting when required
- Communicating directly with customers regarding technical questions during projects
- Previous hands-on bug bounty experience
- Practical experience finding and reporting vulnerabilities through bug bounty or vulnerability disclosure programs
- Practical penetration testing experience
- Strong understanding of common web application and API vulnerabilities
- Good knowledge of OWASP testing methodologies and common vulnerability classes
- Ability to manually reproduce and validate vulnerabilities
- Ability to assess the real security impact of a vulnerability
- Ability to manage smaller penetration testing projects independently
- Clear and structured technical writing
- Ability to communicate professionally with customers and ethical hackers
- Ability to work independently and take responsibility for assigned projects and vulnerability reports
- Hungarian language proficiency
- Legal eligibility to work in Hungary
- Ability to work from Budapest office at least once per week
- OSCP or another relevant offensive security certification
- Experience with mobile application penetration testing
- Experience with infrastructure or cloud penetration testing
- Previous experience with vulnerability triage or managing bug bounty programs
- Experience communicating directly with customers during penetration testing projects
- Strong public bug bounty track record