Career Guides Business Solutions

Offensive Security Engineer, Offensive Security

by Coinbase in
7 (views)

Job role insights

  • Date posted

    May 28, 2025

  • Closing date

    June 22, 2025

  • Hiring location

    India

  • Qualification

    Bachelors

  • Experience

    2 - 3 Years

Description

Ready to be pushed beyond what you think you’re capable of?At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system.

To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems.

Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be.

About the Role

The Application Security organization at Coinbase is seeking to hire an experienced Offensive Security Engineer specializing in bug bounty program management and optimization. In this role, you will work with the Bug Bounty Program Lead and drive bug bounty triage and validation. You will also support strategic bug bounty initiatives aimed to increase program efficiency, maturity and hacker engagement. You will collaborate with whitehat hackers, security engineers, and cross-functional teams to enhance the security posture of the company through an effective bug bounty program.

What you’ll be doing:

  • Participate in bug bounty triage and validation, ensuring timely and accurate assessments.
  • Develop and implement strategies to incentivize and attract high-quality bug bounty submissions.
  • Help manage the bug bounty program, including scope updates, researcher communication and bug bounty payout disbursements.
  • Analyze bug bounty data to identify trends, common vulnerabilities, and areas for security improvement.
  • Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
  • Mentor and train junior security engineers in bug bounty triage and analysis.
  • Provide on-call support for critical bug bounty related incidents.
  • Document and report on bug bounty metrics and program effectiveness.
  • Conduct internal penetration testing engagements on web and mobile applications and services.
  • Participate in red team activities to identify weaknesses in security controls, as well as network and application-level security boundaries.

What we look for in you:

  • A Bachelor’s degree in Computer Science, Computer Engineering, or a related field.
  • Relevant security certifications (e.g., OSCP, GPEN).
  • Experience in programming languages such as Go, JavaScript, Python or Ruby.
  • 2+ years of experience in application security, bug bounty triage, or offensive security roles.
  • Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25)
  • Experience with bug bounty programs and platforms.
  • Strong analytical skills to identify trends and patterns in bug bounty submissions.
  • Excellent communication skills to effectively communicate with researchers and internal teams.
  • Passion for security and a drive to improve bug bounty program efficiency and effectiveness.
  • Ability to work independently and take ownership of the bug bounty program.

Nice to haves:

  • Experience performing red team activities of company products and services.
  • Experience pentesting AI products and features.
  • Contributions to the security community, particularly through bug bounty programs.
  • Experience in Web3 security, network security and/or cloud security.
  • Experience with developing and implementing security tooling to support bug bounty triage and analysis.
PID : P69661
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Call employer
Apply now
Send message
Cancel