Designing for zero trust in cybersecurity

At Bugcrowd, I worked on researcher-facing product experiences and the Design System behind them. The work helped me understand how product clarity and system consistency need to grow together.

Role

Design system Product design Design research

Year

June 2019 - September 2021

Bugcrowd is a cybersecurity platform that connects organisations with a global community of security researchers, often referred to as hackers in the community. During my time on the Product Design team, I worked on the researcher side of the platform: the places where researchers discover programs, understand what needs attention, and stay connected with important program updates.

My work was spread across three connected areas: researcher experience, researcher success and program discovery, and the Design System. I worked from research and problem framing to interaction design, visual design, responsive behaviour, implementation details, PR collaboration, and documentation for designers and engineers.

The case study is therefore not only about one product surface. It is also about how the product work revealed patterns that needed to be understood, documented, and reused.

Context and problem

Researchers had to go to multiple places to understand updates, tasks, programs, payments, and performance. Email carried too much important communication, which made it easy for researchers to miss program announcements or lose track of what needed action.

The existing dashboard behaved more like a profile and performance page than a useful home base. It showed some important information, but it did not clearly help researchers understand what changed, what mattered, and what to do next.

Program discovery had related friction. Researchers needed to evaluate programs based on relevance, scope, technology, payout, timing, and application status, but the experience had issues around loading, filtering, and clarity.

The work happened inside an existing product with real design debt, technical constraints, and incomplete measurement.

Reframed challenge

How might we make Bugcrowd feel like a clearer working place for researchers, while turning recurring interface problems into reusable product patterns?

Designing for researchers

The Researcher Dashboard was the main product-design thread of my Bugcrowd work. The objective was to turn the dashboard into a central hub for tasks, activity, program updates, performance, rewards, and next steps.

The challenge was not just to add more information. Researchers already had too much scattered information. The better question was how to organize the right information into an interface that helped them make decisions without depending on email.

I synthesized researcher and stakeholder feedback, explored dashboard patterns, and worked through an interaction model based around cards for activity, tasks, announcements, and program content. The card model let different types of content share a common structure while still supporting different states, lengths, and levels of detail.

The design work included responsive navigation, expandable content, filters, collapsible sidebar behavior, and light and dark mode considerations. I also collaborated with engineering on implementation details and PR feedback, including layout simplification, icon reuse, copy consistency, and how product-specific needs should work with the Design System rather than fight it.

We wanted active researchers to understand their rewards, tasks, and recent activity quickly. At the same time, returning researchers needed a way to discover relevant programs and get back into security research without having to rebuild context from several places.

The design is responsive so researchers can check their status on different devices.

In the end, the dashboard became a clearer in-product place for important researcher updates. It reduced reliance on email for program communication, made important information easier to find, and supported stronger dashboard engagement.

The announcement column on the right and the summary column on the left can collapse to support different working modes.

The new dashboard was launched in November 2020 and received positive feedback from the Hacker Success team and researchers. As of August 2026, the Bugcrowd docs page still describes the Researcher Dashboard as a hub for rewards, engagements, tasks, activity, and announcements.

One of our Researcher Success managers forwarded a researcher's feedback to our product channel.

One design detail I am proud of is the collapsible layout behaviour. It allowed the dashboard to support different working modes without forcing all information to compete for attention at the same time. The design received positive feedback from our product team.

A layout pattern I proposed in the Design System.

The dashboard also exposed recurring product needs that belonged beyond a single screen: cards, stats, trends, spacing, responsive layouts, link colour, and content patterns. This made the Design System work feel closely related to the product work, rather than a separate track.

Design System work

While the dashboard was the user-facing project, I also contributed to Bugcrowd’s Design System with a focus on design-code parity and developer experience.

The challenge was that product work needed more than static design files. It needed shared patterns and clearer guidelines that designers and engineers could refer to when building product screens.

I researched design-system examples and content guidelines, including how other teams documented tone, numbers, labels, and component usage. I also learnt React, TypeScript, Storybook, Sass variables, icon behaviour, and component styling. It helped me understand how design system can solve real product details such as dashboard layout, icon usage, copy, spacing, and responsive patterns.

The impact was partly product-facing and partly team-facing. The Design System work supported more consistent UI decisions and gave me a stronger shared language with engineers when discussing how product designs should be implemented.

Some of my work included:

Foundations. I worked on link colour because the Bugcrowd platform uses links heavily for navigation. The adjusted blue helped links stay prominent while remaining coherent with both light and dark themes. I also worked on spacing helpers so engineers could match design spacing more quickly.

Layouts. I contributed to common layouts to help raise the bar for design consistency. I also researched, designed, and implemented horizontal scroll in tables so large tables could work across supported screen sizes.

Components. I worked on trust badges, which help visualize the Trust score in CrowdMatch, the product that matches researchers and bounty programs. I also worked on Trend and Stats, which helped power the dashboard project.

Horizontal scroll in tables helped dense data stay usable across supported screen sizes.

Beyond the dashboard and Design System work, I also contributed to smaller product areas that helped round out the researcher experience.

Program discovery and personalised programs. I researched how researchers choose programs and explored ways to make relevant programs easier to find. This included curated categories such as Trending or Quick Payout, and research into what information researchers actually use when deciding whether to participate.

Joinable and waitlisted program flow. I captured pain points around repeated application text, unclear application timing, and poor visibility into which programs researchers had already applied to. The notes point to potential solutions such as reusing past application text and making application status clearer.

Researcher skill tags and staff endorsement. I defined early requirements for staff-endorsed researcher traits that could be used in contexts such as CrowdMatch, submissions, and admin researcher profiles. This included thinking through autocomplete, explanation text, strength scores, and where endorsements should be visible.

Commenting. I designed a comment box that supported Markdown, private comments, and file attachments while being embedded in various contexts across the platform. Working with full-stack engineers, I styled and polished the functional UI to match the intended design.

Editing a private comment.

Results

The product impact was a clearer researcher hub, less dependence on email, and better support for program engagement. The dashboard work helped move important updates into the product experience and gave researchers a more coherent place to understand what needed attention.

The team impact was a stronger shared language between design and engineering. The work around Design System research, component behaviour, and product implementation details helped reduce the gap between design intent and implementation.

The personal impact was learning how product craft and system craft reinforce each other. At Bugcrowd, I grew as a hybrid designer working across research, systems, visual design, and front-end constraints.

Reflection

What worked best was connecting research, UI systems, and implementation. The dashboard became stronger when it was treated not only as a screen, but as a system of content, states, navigation, and reusable patterns. The Design System work also became more meaningful when it was connected back to specific product problems.

What was hard was working through design debt while patterns were still evolving. The card model, responsive behaviour, and design-system constraints all had to be solved inside a live product rather than in a clean-room process.

I learnt that product craft and system craft are connected, but not automatically. They become connected through specific moments: a layout that needs to adapt better, a component that needs clearer behaviour, a label that needs to communicate intent, or a piece of feedback that reveals what the interface failed to explain. The work in Bugcrowd made this relationship visible to me.