Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Bug Bounty Program information
What are some common challenges faced by professionals managing a bug bounty program?
What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?
What is a bug bounty program?
What is the difference between Bug Bounty Program vs Penetration Tester?
| Aspect | Bug Bounty Program | Penetration Tester |
|---|---|---|
| Credentials | Knowledge of security vulnerabilities, bug reporting skills | Certifications like OSCP, CEH, CISSP often preferred |
| Work Environment | Remote, project-based, crowdsourced | Consulting firms, in-house teams, on-site or remote |
| Industry Usage | Tech companies, startups, open security initiatives | Security firms, corporate security teams, government agencies |
| Search/Comparison Intent | Understanding crowdsourced bug finding vs professional testing | Comparing freelance or company-based security assessments |
The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

Full-time
Posted 7 days ago
Caesars Entertainment rating
6.4
Based on 254 frontline employees who took The Breakroom Quiz
108th of 162 rated casinos
Job description
As a Information Security Senior Architect, you will contribute to significantly building the foundation of the offensive security team. This will include performing industry research on various threats, and being a SME on internal security architecture and design that would allow the offensive security team to understand areas of weakness or vulnerabilities to enhance enhancing the firm's cybersecurity or resiliency posture. The senior architect will assist in developer of process and procedure for the offensive security team as it builds out a world class team.
The Information Security Senior Architect will play a role in researching various technologies across many different proficiencies. The successful candidate will be able to demonstrate a general knowledge of computer networking fundamentals, modern threats and vulnerabilities, attack methodologies, and penetration testing tools. The Offensive Security Team consists of highly skilled and qualified members who conduct advanced adversary emulation operations to replicate cybersecurity threats targeting the firm.
Responsibilities
- Manage Pen Testing Engagements - Ability to coordinate with internal teams, applications owners, and 3rd party vendors for various pen testing engagements
- Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business lines and vendors
- Policy and Procedures - Assist in policy and process development for the Offensive Security Team amongst various teams and disciplines (cyber threat intelligence, threat hunting, adversary emulation)
- Conduct Threat Assessments and Threat Research: Explore various technologies and solutions to understand information security risks and weaknesses. Perform threat research on various industry threats, vulnerabilities, and attack vectors to understand potential weaknesses in security defenses and where security mitigations need to be enhanced.
- Threat Modeling: Conduct threat modeling assessments to understand most relevant threats to Caesars
- Lead cross-team educational sessions and training: Lead sessions across internal security teams and across the entire company that detail relevant threats and information that business professionals need to understand as the threat landscape evolves
- Collaboration: Collaborate closely with IT and Security teams to understand the current security architecture and help develop strategies to mitigate identified risks. Conduct Purple Team exercises with the SOC to test, validate, and improve the effectiveness of existing security controls.
- Compliance: Ensure that penetration testing activities adhere to relevant compliance standards and regulations, including those specific to the casino industry such as PCI-DSS and other gaming regulations.
- Continuous Improvement: Stay current with the latest security trends, techniques, and vulnerabilities, and apply this knowledge to continuously improve the security posture of the firm.
- Training and Awareness: Provide guidance and training to internal teams on security best practices and how to address identified vulnerabilities.
Qualifications
- 3-5 years of experience in cybersecurity with a focus on threat research or analysis.
- Experience with security tools and technologies, such as SIEM, next generation firewalls, endpoint protection, and threat intelligence platforms
- Strong understanding of the following: networking fundamentals (all OSI layers, protocols); Windows/Linux/Unix/Mac operating systems as well as software vulnerability and exploitation techniques
- Familiarity with system administration skills such as configuration, maintenance, and interpretation of log output from networking devices, operating systems, and infrastructure services, as well as with cloud architecture, operations, and security vulnerabilities
- Experience in multiple businesses or verticals, with organizational and cultural understanding of call centers, payments processes, and client service/sales organizations
- Expertise in collaborating with high-performing teams and individuals throughout the firm to accomplish common goals
- Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
- Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents
About Us
At Caesars Entertainment, Inc., our Team Members create the extraordinary. We are the largest casino-entertainment company in the U.S. and one of the world's most diversified casino-entertainment providers. Since beginning in Reno, Nevada, in 1937, Caesars Entertainment has grown through the development of new resorts, expansions and acquisitions. Our resorts operate primarily under the Caesars®, Harrah's®, Horseshoe® and Eldorado® brand names. We focus on building loyalty and value with our guests through a combination of impeccable service, operational excellence and technological leadership. The company is committed to its Team Members, suppliers, communities and the environment through its PEOPLE PLANET PLAY framework.
Our Caesars family is driven by our Mission, Vision and Values. We take great pride in living these values - Together We Win, All In On Service and Blaze the Trail - every day. Our mission, "Create the Extraordinary". Our vision, "Create spectacular worlds. That immerse, inspire and connect you. We don't perform magic; we create it with excellence. #WeAreCaesars". If you are ready to create some magic, we invite you to explore our dynamic, yet unique, career opportunities.
What Caesars Entertainment employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Caesars Entertainment
Sourced by ZipRecruiter
Industry
Hospitality services
Company size
10,000+ Employees
Headquarters location
Las Vegas, NV, US
Year founded
1937