- Lead Offensive Security Engagements: Own and execute complex, end-to-end internal penetration tests against Bazaarvoice's most critical applications, infrastructure, and cloud environments. You will simulate advanced, multi-stage attack scenarios to uncover systemic security weaknesses before they can be exploited.
- Program and Tooling Enhancement: Take a lead role in defining the strategy for our offensive security capabilities. You will research, prototype, and implement new tools, techniques, and automation to mature our testing processes and keep pace with the evolving threat landscape.
- Strategic Third-Party Penetration Test Management: Act as the primary technical lead for our third-party penetration testing program. You will not only manage the engagement lifecycle but also define the strategic direction of our testing roadmap, ensuring we partner with providers to target the highest-risk areas of our business.
- Bug Bounty Program Leadership: Design, lead, and operate all aspects of our bug bounty program, serving as the technical interface for third-party researchers and coordinating internal responses to submitted vulnerability findings, ensuring clear communication and timely resolution.
- Mentorship and Technical Leadership: Mentor junior team members and act as a security champion and trusted advisor to engineering teams. You will elevate the security knowledge across the organization by leading training sessions, developing secure coding guidelines, and providing expert consultation on secure architecture.
- Threat Modeling: Proactively engage with development teams early in the SDLC to conduct threat modeling exercises, helping them build more secure products from the ground up.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience with 10+ years of related experience.
- 7+ years of hands-on experience in offensive security, with a strong background in penetration testing, red teaming, or application security.
- Operational Cloud Expertise: 3-5 years of hands-on experience operating in, managing, or performing manual penetration tests of cloud infrastructure (AWS preferred), with a deep understanding of cloud-native attack vectors (e.g., IAM exploitation, container escapes, and serverless security).
- Expert-level knowledge in managing the lifecycle of penetration testing engagements and a proven track record of driving remediation efforts in a complex, multi-team environment.
- Deep and practical understanding of common and advanced vulnerability classes (OWASP Top 10 and beyond) and the ability to architect solutions to remediate them at scale.
- High proficiency in one or more scripting languages (e.g., Python, Go, Bash) for advanced tool development and automation of complex tasks.
- Exceptional communication and interpersonal skills, with a demonstrated ability to influence technical and non-technical stakeholders at all levels, including senior leadership.
- A proven history of mentorship and a passion for elevating the skills of those around you.
- Advanced offensive security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or equivalent.
- Deep expertise in AWS cloud security operations and infrastructure-as-code security.
- Experience building and maturing an offensive security program or function.
- Demonstrated experience leading red team or purple team exercises.
- Published security research, conference presentations, or active contributions to the open-source security community.
- Experience in a Security Development Lifecycle (SDL) environment and a history of implementing DevSecOps principles.
Why You’ll Love Working with Us?Work with cutting-edge tech in an innovative, collaborative environment.Competitive salary + good benefits (insurance, annual leave, bonuses, referral rewards, and more).We’reGreat Place to Work Certified (3 years in a row!).Hybrid work model (3 days in office – Prestige Tech Pacific, Kadubeesanahalli).Interview Process:Tech Round 1Tech Round 2Hiring Manager Meeting: Team, values & culture check.Final Round: Chat with HR/Senior Leadership.Disclaimer:All Official communications from Bazaarvoice recruitment originates strictly from our verified domain (@bazaarvoice.com). Bazaarvoice does not send recruitment emails from different domains.
Bazaarvoice never requests payment / financial deposits as part of our selection process. All legitimate career opportunities and application details are listed on our official careers page. (https://www.bazaarvoice.com/company/careers/)
Bazaarvoice is not responsible for any unauthorized emails or interactions originating outside the official web domain.
Skills Required
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent practical experience
- 7+ years hands-on experience in offensive security (penetration testing, red teaming, or application security)
- 3-5 years hands-on experience operating in or testing cloud infrastructure (AWS preferred); deep understanding of cloud-native attack vectors
- Expert-level experience managing the lifecycle of penetration testing engagements and driving remediation in complex environments
- Deep practical understanding of common and advanced vulnerability classes (OWASP Top 10 and beyond) and remediation at scale
- High proficiency in one or more scripting languages for tooling and automation (e.g., Python, Go, Bash)
- Exceptional communication and interpersonal skills; ability to influence technical and non-technical stakeholders and senior leadership
- Proven history of mentorship and elevating others' security skills
- Advanced offensive security certifications (OSCP, OSWE, OSEP, GPEN, GXPN) or equivalent
- Deep expertise in AWS cloud security operations and infrastructure-as-code security
- Experience building and maturing an offensive security program, leading red team or purple team exercises
- Published security research, conference presentations, or open-source security contributions
- Experience in Security Development Lifecycle (SDL) and implementing DevSecOps principles
Bazaarvoice Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bazaarvoice and has not been reviewed or approved by Bazaarvoice.
-
Leave & Time Off Breadth — Time off is considered flexible, with unlimited PTO and paid volunteer time available alongside a hybrid/flexible-remote setup. Paid sabbaticals after a tenure milestone are highlighted as part of the package.
-
Parental & Family Support — Paid parental leave for primary caregivers is consistently presented as a strong component of the offering. Family medical leave options are also documented.
-
Wellbeing & Lifestyle Benefits — Mental health support via a dedicated platform, recognition programs, ERGs, and a companywide volunteering tradition are emphasized. Company events and regular all-hands reinforce a wellbeing and community focus.
Bazaarvoice Insights
What We Do
Each month in the Bazaarvoice Network, more than a billion consumers create, view, and share authentic user-generated content including reviews, questions and answers, and social photos across more than 11,500 global brand and retailer websites. From search and discovery to purchase and advocacy, Bazaarvoice’s solutions help brands and retailers reach in-market shoppers, personalize their experiences, and give them the confidence to buy.









