Company Description Vulzero CyberSecurity Inc, founded in 2024 in Cambridge, Ontario, focuses on embedding provable security knowledge into every client engagement. The company is dedicated to preserving and transferring security expertise to prevent knowledge gaps and ensure long-term protection. Vulzero emphasizes transparent, evidence-based security practices that avoid vague explanations such as “the AI did it.” Team members contribute to building robust, auditable security solutions for diverse environments. The organization values continuous learning, technical rigor, and clear communication of security risks and mitigations.
Role Description This is a part-time, on-site Bug Bounty Hunter role based in Toronto, ON. The Bug Bounty Hunter will identify, validate, and document security vulnerabilities across web applications, APIs, mobile apps, and infrastructure targets defined by Vulzero and its clients. Daily tasks include performing structured and exploratory penetration testing, reproducing reported issues, collecting proof-of-concept exploits, and assessing impact and risk. The role involves collaborating with security engineers and developers to clarify findings, assist with remediation guidance, and support coordinated disclosure processes. The Bug Bounty Hunter will also help refine testing methodologies, update internal knowledge bases, and contribute to reports and presentations that capture clear, provable security insights.
Qualifications
- Hands-on skills in vulnerability discovery, including manual testing, fuzzing, and exploit proof-of-concept development.
- Knowledge of common web and application vulnerabilities (e.g., OWASP Top 10), secure coding concepts, and threat modeling.
- Experience with penetration testing tools and platforms (such as Burp Suite, OWASP ZAP, Nmap, or bug bounty platforms).
- Ability to clearly document findings, including steps to reproduce, impact analysis, and suggested remediation.
- Strong analytical and problem-solving skills, with attention to detail and a methodical testing approach.
- Comfort working on-site in a lab or office environment and collaborating with cross-functional technical teams.
- Familiarity with Linux environments, scripting (e.g., Python, Bash, or JavaScript), and basic networking concepts is beneficial.
- Relevant certifications or training (e.g., OSCP, eJPT, or equivalent practical experience) are an asset.
- Commitment to ethical hacking practices, confidentiality, and responsible vulnerability disclosure.