Full-Time

Junior Penetration Tester

Posted on 9/26/2025

Bugcrowd

Bugcrowd

1,001-5,000 employees

Crowdsourced cybersecurity platform for vulnerability discovery

No salary listed

Remote in UK

Remote

Category
IT & Security (1)
Requirements
  • Experience: 6+ months as a penetration tester (or equivalent demonstrable experience) with a foundational understanding of wider cybersecurity concepts and best practices.
  • Technical Skills: Familiarity with commonly used security testing tools (e.g. BurpSuite, Nmap) and approach to penetration testing activities.
  • Soft Skills: Strong desire to learn, good communication skills for peer and mentor interactions, and the ability to follow instructions.
  • Strong written and spoken business English (C1+ or native fluency).
  • Certifications: CEH (Certified Ethical Hacker), OSCP(+) (Offensive Security Certified Professional), CPSA (CREST Practitioner Security Analyst), etc. are considered a plus.
Responsibilities
  • Conduct Structured Testing to Identify Security Vulnerabilities: Demonstrating a functional understanding of modern attack vectors and penetration testing software as well as being technically capable of using them in the identification of security vulnerabilities in Web applications, APIs and network infrastructure.
  • Consistently complete assigned penetration tests within allocated timeframes, and in accordance with our methodologies.
  • Continuous Learning: Actively engage in keeping up-to-date with fundamental security concepts and core testing tools, applying newly acquired knowledge under instruction and supervision.
  • Problem Identification & Escalation: Promptly identify and effectively communicate technical blockers or concerns to mentors or Technical Pentest Managers (TPMs) as needed, actively seeking clarification and guidance to avoid missteps.
  • Team Support & Documentation: Assist in test retrospectives, documentation of processes, and provide support to more senior team members as directed by the team lead or manager.
  • Working Hours: Be able to execute testing within UK core business hours (09:00 - 17:30 GMT). Some tests may fall outside of these hours, but the majority of tests will need to be completed within this timeframe.
Desired Qualifications
  • 6+ months as a penetration tester (or equivalent demonstrable experience) with a foundational understanding of wider cybersecurity concepts and best practices.
  • Familiarity with commonly used security testing tools (e.g. BurpSuite, Nmap) and approach to penetration testing activities.
  • Strong written and spoken business English (C1+ or native fluency).
  • Certifications such as CEH (Certified Ethical Hacker), OSCP(+) (Offensive Security Certified Professional), CPSA (CREST Practitioner Security Analyst), etc. are considered a plus.
  • Certifications: CEH, OSCP, CPSA are considered a plus.

Bugcrowd runs a platform that connects businesses with a global community of security researchers to find and fix vulnerabilities in digital systems. It mainly runs bug bounty programs where companies offer rewards for researchers who report bugs, and it also provides services like attack surface management and remediation guidance. Researchers submit security findings through the platform, which coordinates the workflow, payments, and follow-up actions. The company differentiates itself by leveraging a large, global crowd of researchers and offering integrated services and compliance support (PCI DSS, GDPR, SOC 2, ISO 27001) in addition to bug bounties. Its goal is to help clients continuously improve their security posture and meet regulatory requirements by uncovering and addressing security risks before attackers can exploit them.

Company Size

1,001-5,000

Company Stage

Late Stage VC

Total Funding

$230.7M

Headquarters

San Francisco, California

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • AWS ISV Accelerate Program unlocks direct field sales access to enterprise cloud customers.
  • AI Connect with Model Context Protocol positions Bugcrowd as security infrastructure layer.
  • Dynamic SBOM and reinforcement learning automate supply chain risk remediation at scale.

What critics are saying

  • HackerOne's superior payouts drive researcher migration, reducing Bugcrowd's vulnerability discovery effectiveness.
  • Intigriti's 20% pricing undercut captures European financial institutions and GDPR-focused clients.
  • OpenAI's GitHub Copilot vulnerability scanning API collapses developer-paid bug bounty demand.

What makes Bugcrowd unique

  • Mayhem acquisition integrates AI fuzzing with crowdsourced testing across full SDLC.
  • AI Triage Assistant and Analytics reduce manual vulnerability triage by 60-80%.
  • Crowdsourced Red Team as a Service offers real-time intelligence-led adversarial testing.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive salary & stock options

Opportunities to attend & host relevant conferences & meetup

Flexible vacation time

Medical, dental & vision coverage

Generous workstation allowance

Company-sponsored off-sites & celebrations

Pre-tax commuter benefits

401k

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
SecurityInformed.com
Dec 11th, 2025
Bugcrowd Launches AI Triage For Security Resilience

Bugcrowd launches AI Triage for security resilience. Bugcrowd, recognized for its significant contributions to crowdsourced cybersecurity, has introduced advanced functionality to its platform with the release of the Bugcrowd AI Triage Assistant and Bugcrowd AI Analytics. This development aims to enhance the speed and intelligence involved in building security resilience. Along with the general release of AI Connect, these features are designed to empower security teams to make proactive decisions, thereby addressing emerging threats before they occur. Introducing Bugcrowd's new AI capabilities. As attackers increasingly utilize AI tools and the complexity of attack surfaces grows, security professionals require efficient solutions that minimize manual efforts. Bugcrowd's AI advancements eliminate dependency on unsanctioned third-party large language models and replace time-consuming research with precise, environment-specific insights. Consequently, security analysts can accelerate triage processes, uncover hidden patterns, and make strategic decisions that bolster resilience against potential threats. AI Triage Assistant and AI Analytics features. Bugcrowd's AI advances eliminate dependency on unsanctioned third-party large language models "With the rapid pace of sophisticated AI-driven attacks, our goal is to help customers make faster, better decisions affecting their security strategy, including ones that set the foundation for preemptive security. AI Triage Assistant and AI Analytics are central to that mission," stated Braden Russell, CPO of Bugcrowd. "It's not about replacing human intuition, but augmenting it with powerful AI insights. Using that approach to help security teams see the bigger picture within each submission, as well as the hidden trends affecting the whole organization, we're enabling them to make smarter, faster decisions that fundamentally improve their organization's security posture." Enhanced dashboard utilities. The AI Triage Assistant acts as a secure conversational AI agent, revolutionizing the efficiency of vulnerability triage by providing instant, contextual insights related to specific vulnerabilities. Complementing this, AI Analytics offers organization-level intelligence, delivering AI-powered dashboards that transform static security reporting into an interactive experience. Key components of Bugcrowd's AI tools. Bugcrowd AI Analytics provides instant and precise responses about security status, organizational trends Bugcrowd AI Triage Assistant offers real-time risk identification, allowing analysts to quickly assess security risks with in-depth insights. It simplifies complexity with prompt start options for clear analysis and deep technical insights through straightforward questions. Additionally, it supports strategic analysis by offering a broader perspective on trends across testing programs. Bugcrowd AI Analytics provides instant and precise responses about security status, organizational trends, and tester performance. It helps identify the driving forces behind trends to enhance decision-making efficiency and demonstrates progress and impact across all security testing operations. AI Connect now generally available. Bugcrowd also announced the wide availability of AI Connect, which was initially released in beta in August. AI Connect allows users to integrate their AI systems securely with live vulnerability data from the Bugcrowd Platform through Model Context Protocol, a standard for connecting AI models to external resources. Dr. David Brumley, Chief AI and Science Officer at Bugcrowd, emphasized the importance of these innovations in navigating the complex modern attack surfaces. "Our recent AI innovations represent our vision for the future of security testing - where human creativity and machine speed work in harmony. By investing heavily in AI capabilities that complement our global hacker community, we're delivering a platform that doesn't just find vulnerabilities but transforms how organizations understand and manage their security risk landscape."

SourceSecurity.com
Dec 11th, 2025
Bugcrowd AI enhancements in security

Bugcrowd AI enhancements in security. Bugcrowd, recognised for its work in crowdsourced cybersecurity, has recently unveiled new platform enhancements, introducing Bugcrowd AI Triage Assistant and Bugcrowd AI Analytics. These technologies aim to enhance the speed at which security resilience can be developed by offering improved intelligence and insights. Alongside the general release of AI Connect, these features are designed to support security teams in making quicker, more informed decisions to preemptively address emerging threats, rather than react after vulnerabilities have already been exploited. Innovative additions to Bugcrowd's AI capabilities. Bugcrowd's latest AI features are designed to enable security analysts to speed up triage processes In response to the increased pace of attacks using AI tools and the growing complexity of attack surfaces, Bugcrowd has developed solutions that aim to reduce manual processing, provide secure, real-time intelligence, and promote a proactive security approach. By removing dependence on unsanctioned third-party large language models (LLMs) and shifting from time-consuming research to providing environment-specific insights, Bugcrowd's latest AI features are designed to enable security analysts to speed up triage processes, uncover hidden trends, and make strategic decisions that reinforce resilience before threats emerge. Introducing AI Triage Assistant and AI Analytics. Commenting on the latest developments, Braden Russell, Bugcrowd's Chief Product Officer, stated, "With the rapid pace of sophisticated AI-driven attacks, our goal is to help customers make faster, better decisions affecting their security strategy, including ones that set the foundation for preemptive security. AI Triage Assistant and AI Analytics are central to that mission." He added that the purpose is not to replace human intuition but to enhance it with robust AI insights, enabling security teams to perceive the overarching picture of each submission and detect hidden trends across the organisation for more informed decision-making. Enhancing security through AI-powered dashboards. AI Triage Assistant functions as a conversational AI agent focused on boosting vulnerability triage efficiency by offering instant, contextual details on specific vulnerabilities. Meanwhile, AI Analytics enhances this by delivering intelligence at an organisational level through AI-powered dashboards, transforming static security reports into interactive, conversational experiences. These advancements permit security teams to swiftly transition from intricate analysis to decisive actions within seconds. Key features of Bugcrowd's AI solutions. Bugcrowd AI Triage Assistant. * Provides real-time risk assessments with immediate insights into specific vulnerabilities, allowing analysts to quickly identify potential security threats. * Simplifies complexity with prompt starters for quick comprehension of intricate findings and offers plain-language follow-up queries for deeper technical insights. * Facilitates strategic understanding by enabling broad analysis of trends across various testing programs. Bugcrowd AI Analytics. * Delivers instantaneous, precise answers regarding security posture, organisational trends, and tester effectiveness. * Clarifies trend drivers, offering insights into the factors influencing trends, such as an increase in certain vulnerability types, leading to improved security decisions. * Measures impact across security testing to evaluate its effectiveness and track progress organisation-wide. The general availability of AI Connect was also announced, following its beta release in august. AI Connect facilitates customers' secure integration of their internal AI frameworks with real-time vulnerability data sourced from the Bugcrowd platform utilising model context protocol (MCP), a developing standard for linking AI models to external tools, data repositories, and software. Dr. David Brumley, Bugcrowd's Chief AI and Science Officer, noted, "Security teams today face unprecedented challenges in managing the growing complexity of modern attack surfaces. Our recent AI innovations represent our vision for the future of security testing - where human creativity and machine speed work in harmony. By investing heavily in AI capabilities that complement our global hacker community, we're delivering a platform that doesn't just find vulnerabilities but transforms how organisations understand and manage their security risk landscape." Discover how AI, biometrics, and analytics are transforming casino security

Help Net Security
Nov 4th, 2025
Bugcrowd expands AI-powered, human-led security with Mayhem Security acquisition

Bugcrowd expands AI-powered, human-led security with Mayhem Security acquisition. Bugcrowd has announced the acquisition of Mayhem Security to advance the next generation of AI-powered, human-in-the-loop security testing. Bugcrowd aims to help organizations ship safer software faster, at lower cost, and with greater confidence, while shrinking their attack surface. The terms of the transaction were not disclosed. Organizations face increasingly complex attack surfaces, driven by rapid software delivery, expanding APIs, and opaque supply chains. Traditional security approaches often detect vulnerabilities only after deployment, leaving exploitable weaknesses in production and exposing businesses to escalating risks from adversaries who operate with increasing speed and sophistication. Addressing these challenges requires a new approach, one that combines the scalability and precision of AI with the contextual insight of human-led testing to deliver security that evolves as fast as the threats it defends against. The integration of Mayhem's AI-driven automation with Bugcrowd's crowdsourced testing redefines how vulnerabilities are discovered and remediated across the software development lifecycle. Customers will gain automated, proactive protection during development through virtually noise-free testing that continuously finds, prioritizes, and validates the remediation of vulnerabilities, seamlessly complemented by Bugcrowd's human-driven adversarial testing of deployed software by trusted, highly skilled hackers. By combining Mayhem's AI offensive security with Bugcrowd's crowdsourced expertise, organizations can continuously reduce their attack surface, eliminate risky code and dependencies, and keep pace with adversaries. "This acquisition represents another milestone in our mission to transform the way organizations approach cybersecurity by combining the collective ingenuity of our global hacker community with the machine speed and precision of AI offensive security testing", said Dave Gerry, CEO of Bugcrowd. "By integrating Mayhem's capabilities into the Bugcrowd Platform, we're building the industry's first truly adaptive security platform, enabling customers to anticipate, test, and defend at unprecedented scale. This is a strategic step toward realizing our vision of a self-learning platform that unites human creativity with machine intelligence, while shrinking customers' attack surface," Gerry continued. * API security - Replaces biased and cumbersome manual methods with continuous, automated penetration testing to find, validate, and fix API vulnerabilities with 100% accuracy. * Code security - Enables customers to ship or deploy secure code faster and at a lower cost compared to noisy, time-consuming manual testing. * Dynamic SBOM - Simplifies and accelerates time-to-compliance by profiling runtime applications and automatically identifying and removing risky third-party dependencies and unused code. * Reinforcement learning - Trains agents to carry out actions and solve problems by learning to run, break, and pass tests in real software. "For over a decade, we've built technology that thinks and learns like an attacker to autonomously find new vulnerabilities. Joining forces with Bugcrowd amplifies that mission by combining AI-driven automation with the creativity and expertise of the global hacker community. Together, we're redefining modern security testing, helping organizations preempt risk, close vulnerabilities faster, and eliminate zero-day threats," said Dr. David Brumley, CEO of Mayhem Security. "Bugcrowd's acquisition of Mayhem Security marks a strategic evolution in how cybersecurity drives enterprise growth," said Navin Maharaj, Senior Director at KDT. "As software development accelerates and attack surfaces expand, integrated platforms like Bugcrowd's are uniquely positioned to lead. This move strengthens their market presence and amplifies their ability to deliver long-term value across the enterprise landscape."

SiliconANGLE Media
Nov 4th, 2025
Bugcrowd Acquires AI Security Startup Mayhem

Bugcrowd Inc. has acquired Mayhem Security, an AI offensive security startup, to enhance AI-powered security testing. Mayhem, founded in 2012 by researchers from Carnegie Mellon University, automates the discovery and remediation of software vulnerabilities. Its platform uses AI and methods like symbolic execution and fuzzing to perform offensive security testing, simulating attacker behavior across code, applications, and runtime environments.

TI INSIDE Online
Sep 17th, 2025
A culture of trust and direct feedback is a pillar of digital resilience, says Trey Ford

On the second day of Mind The Sec 2025 in São Paulo, Trey Ford, CISO at Bugcrowd, brought a unique approach to technology and security executives.

INACTIVE