> Markdown version of [/jobs/ext/2722680-security-analyst](https://www.wearedevelopers.com/jobs/ext/2722680-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** RunSybil Corp. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $130,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, Programming Tools, Open Web Application Security, Software Engineering, Web Applications, Software Security - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-analyst-runsybil-9627991 ## About the Role This role does not require software engineering experience. It requires deep familiarity with web vulnerabilities, sharp analytical judgment, and the ability to communicate findings precisely. If you have spent time in bug bounty, application security, or pentesting and have a strong eye for what is real and what is noise, we want to hear from you., * 2 or more years of hands-on experience with web application vulnerabilities through bug bounty, penetration testing, application security, or a similar role * Solid, practical understanding of OWASP Top 10 and common web vulnerability classes: you have actually found and confirmed these, not just read about them * Experience reproducing and validating findings manually, including in ambiguous or noisy environments * Comfort with tools like Burp Suite, browser developer tools, or similar for hands-on verification * Strong written communication: you can describe a vulnerability, its impact, and how to fix it in plain language * Attention to detail and consistency: you apply the same standard to the hundredth finding that you applied to the first * Self-direction: you manage your own work without needing someone to structure your day ## Description We are looking for a Security Analyst to join our security research team. You will work hands-on with web application vulnerabilities every day, assessing findings, confirming exploitability, rating severity, and delivering clear, accurate reports that customers rely on to understand and remediate their risk., * Assess and validate web application vulnerabilities across a range of targets and confirm exploitability and scope * Reproduce findings hands-on using tools like Burp Suite * Rate severity accurately using established frameworks such as CVSS and OWASP * Write clear, accurate, customer-facing finding descriptions and remediation guidance that security practitioners trust and developers can act on * Maintain consistent standards across a high volume of findings * Surface patterns, edge cases, and unusual behaviors to the broader team * Identify patterns across findings and share feedback on where and how Sybil can improve ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI Pair Programming with GitHub Copilot at SAP: Looking Back, Looking Forward!](https://www.wearedevelopers.com/videos/1546-ai-pair-programming-with-github-copilot-at-sap-looking-back-looking-forward) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)