SecureBlock

Odkrywaj podatności dla klientów, którzy naprawdę je naprawiają.

Kolektyw SecureBlock to sprawdzona sieć niezależnych badaczy ofensywnego bezpieczeństwa. Jeżeli jesteś osobą, która odnajduje błąd, który autor raportu podsumuje, i szukałeś miejsca, które płaci uczciwie, przypisuje zasługę bezpośrednio i nigdy nie prosi o napisanie oferty — czytaj dalej.

~4%
Wskaźnik akceptacji
$1.2k
Średnia wypłata dzienna
38
Aktywnych badaczy
14
Reprezentowanych krajów
Kogo szukamy

Specjaliści na pierwszym miejscu. Generaliści mile widziani.

Wybierz jedną dziedzinę i bądź w niej wyjątkowy. Tworzymy zespoły dla zleceń wokół głębokości, nie szerokości CV.

Web app specialists

Business-logic, authentication, and modern-framework exploitation. You know why the OWASP Top 10 is not the interesting part.

Lista kontrolna umiejętności
  • Modern SPA and API testing (React/Vue/Angular)
  • GraphQL schema and resolver attacks
  • OAuth, SAML, and OIDC flow abuse
  • Multi-tenant authorization matrices
Certyfikaty (jeden wymagany)
OSCPOSWEBSCP

Mobile — iOS + Android

From Frida hooks to keychain forensics to backend API tracing — the whole app-plus-backend stack.

Lista kontrolna umiejętności
  • Frida and Objection instrumentation
  • iOS Keychain and Android Keystore review
  • Certificate pinning bypass
  • Deep-link and IPC attack surface
Certyfikaty (jeden wymagany)
OSCPOSMR (SecOps Mobile Reversing)GMOB

Cloud & Kubernetes

AWS, Azure, GCP. IAM graph analysis, Terraform review, cluster escape scenarios. You have opinions about IMDSv2.

Lista kontrolna umiejętności
  • IAM privilege escalation mapping
  • Kubernetes RBAC and admission controller review
  • Terraform/CloudFormation code review
  • Serverless (Lambda, Functions) attack chains
Certyfikaty (jeden wymagany)
OSCPCCSPAWS Security Specialty

Hardware / IoT

Firmware unpacking, JTAG, bus sniffing, RF. The engagements where you actually take the screwdriver out.

Lista kontrolna umiejętności
  • Firmware extraction (SPI/JTAG/eMMC)
  • Binary emulation and static analysis
  • Radio protocol analysis (BLE/Zigbee/LoRa)
  • Fault injection and side-channel basics
Certyfikaty (jeden wymagany)
OSCPOSEEGXPN
Jak to działa

Weryfikacja zajmuje tygodnie, nie minuty.

To jest celowe. Wysoki standard jest powodem, dla którego nasi klienci ufają kolektywowi.

Krok 0110 min

Apply

Submit your profile, specialty, and a short "best find" writeup. Real writeups only — we read them.

Krok 0245 min · live

Technical screen

Video call with two senior testers. Deep technical questions on your primary specialty, no whiteboard puzzles.

Krok 03~8 hrs · async

Practical challenge

A realistic engagement scenario. You get a scope, a target, and a week. We evaluate the process, not just the findings.

Krok 041 week

Reference check

Two references, ideally people who have shipped an engagement with you. We ask about how you work, not just what you found.

Krok 052 weeks

Onboard

Sign the collective agreement, get platform access, shadow one engagement, then lead your first. You are in.

Co otrzymujesz

Model zbudowany dla profesjonalistów, nie dla pracowników gig economy.

Paid fairly, tier-based

Transparent daily-rate tiers. Senior researchers earn $1,400 – $2,200/day. Tiers are published; the ladder is visible.

Choose your engagements

Match engagements to your specialty and calendar. Never assigned to work you did not opt into.

In-house senior leads

Every engagement has a SecureBlock full-time lead. You are not sold as a warm body to a client account manager.

Direct client credit

Your callsign appears in the report. Clients know who found what. Portfolio grows with every engagement.

Private disclosure programmes

Access to a curated list of private VDP and bug-bounty targets that partner with SecureBlock.

No lead-gen or sales work

You never write proposals, never sit in scoping calls, never hunt for logo work. Just the testing.

Z kolektywu

Co mówią obecni członkowie.

"The vetting was serious in a way I hadn't experienced before. The practical challenge was a real target, real business logic, and a real week to work through it. I felt more respected as a tester by the time I passed than by any full-time job I've held."

K. Adebayo @n3rvous
Web app + cloud

"I do this collective a couple weeks per quarter. The rest of the time I run my own research. SecureBlock treats me like a professional, pays on time, and never asks me to fill in a timesheet. I've stopped looking for anything else."

M. Ivanova @byte0
Mobile / Android

"The thing that sold me was that every engagement has a senior in-house lead. I know exactly who I'm reporting to, they know my work, and if I need backup on something novel there is always someone to page."

R. Nakamura @piprock
Hardware / IoT
FAQ

Pytania, które naprawdę zadają badacze.

Napisz do nas, jeżeli Twoje pytanie tu nie ma — odpowiedź przychodzi od człowieka.

Nie. Większość członków kolektywu współpracuje z nami w niepełnym wymiarze — tydzień lub dwa na kwartał to norma. Nieliczni pracują na pełny etat na platformie. Obie opcje są mile widziane.
Rekrutacja otwarta · Q3 2026

Gotowy, aby dołączyć do kolektywu?

Dziesięć minut na wstępną aplikację. Człowiek odpowiada w ciągu jednego dnia roboczego w każdym przypadku.