Our partner is looking for a Bug Bounty Security Researcher based in Netherlands. This is an exciting security research opportunity for a skilled professional passionate about discovering ...
Our partner is looking for a Bug Bounty Security Researcher based in Netherlands. This is an exciting security research opportunity for a skilled professional passionate about discovering ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
$180K - $325K/yr
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
$180K - $325K/yr
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Senior Security Engineer
Los Angeles, CA · On-site
$123K - $169K/yr
Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and ...
Senior Security Engineer
Los Angeles, CA · On-site
$123K - $169K/yr
Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and ...
IT Security Engineer III
San Diego, CA · On-site
Triage incoming bug bounty reports while assessing severity and impact * Provide input into high-quality reports to enable stakeholders understanding of the impact and required remediations based on ...
New
IT Security Engineer III
San Diego, CA · On-site
Triage incoming bug bounty reports while assessing severity and impact * Provide input into high-quality reports to enable stakeholders understanding of the impact and required remediations based on ...
New
Infrastructure Security Engineer
Charleston, WV · On-site
$132K/yr
Core Responsibilities Bug Bounty Program * Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications. * Triage inbound ...
Infrastructure Security Engineer
Charleston, WV · On-site
$132K/yr
Core Responsibilities Bug Bounty Program * Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications. * Triage inbound ...
Software Engineer, Security
San Francisco, CA · On-site
$250K - $350K/yr
You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for ...
Software Engineer, Security
San Francisco, CA · On-site
$250K - $350K/yr
You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for ...
Core Responsibilities Bug Bounty Program * Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications. * Triage inbound ...
Core Responsibilities Bug Bounty Program * Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications. * Triage inbound ...
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
Senior Product Security Engineer
San Jose, CA · On-site
$134K - $184K/yr
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Senior Product Security Engineer
San Jose, CA · On-site
$134K - $184K/yr
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Senior Security Engineer - Product Security
Charlotte, NC · On-site
$111K - $153K/yr
Monitor and report bug bounty program performance metrics and recommend process improvements. * Support governance, risk, and compliance initiatives, including audits and assessments related to PCI ...
Senior Security Engineer - Product Security
Charlotte, NC · On-site
$111K - $153K/yr
Monitor and report bug bounty program performance metrics and recommend process improvements. * Support governance, risk, and compliance initiatives, including audits and assessments related to PCI ...
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Senior Product Security Engineer
San Jose, CA · On-site
$134K - $184K/yr
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Senior Product Security Engineer
San Jose, CA · On-site
$134K - $184K/yr
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Flag systemic or critical findings to Bug Bounty team for partner concern as needed. * Develop dashboards in PowerBI to support data-driven analysis and remediation efforts. What You Need to Succeed
Software Engineer, Security
San Francisco, CA · On-site
$250K - $350K/yr
Operate the bug bounty program, triage vulnerability reports, and coordinate responses. * Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and ...
Quick apply
Software Engineer, Security
San Francisco, CA · On-site
$250K - $350K/yr
Operate the bug bounty program, triage vulnerability reports, and coordinate responses. * Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and ...
Senior Security Engineer
Augusta, GA · On-site
$107K - $147K/yr
Monitor and report bug bounty program performance metrics and recommend process improvements. * Support governance, risk, and compliance initiatives, including audits and assessments related to PCI ...
Senior Security Engineer
Augusta, GA · On-site
$107K - $147K/yr
Monitor and report bug bounty program performance metrics and recommend process improvements. * Support governance, risk, and compliance initiatives, including audits and assessments related to PCI ...
Bug Bounty information
See salary details
$12.98 - $14.16
2% of jobs
$14.16 - $15.34
4% of jobs
$15.34 - $16.52
7% of jobs
$17.55 is the 25th percentile. Wages below this are outliers.
$16.52 - $17.70
13% of jobs
$17.70 - $18.88
19% of jobs
The median wage is $19.22 / hr.
$18.88 - $20.06
15% of jobs
$20.06 - $21.24
12% of jobs
$21.54 is the 75th percentile. Wages above this are outliers.
$21.24 - $22.42
11% of jobs
$22.42 - $23.60
9% of jobs
$23.60 - $24.78
7% of jobs
$24.78 - $25.96
1% of jobs
$12
$20
$25
How much do bug bounty jobs pay per hour?
What is a bug bounty?
A Bug Bounty job involves finding and reporting security vulnerabilities in software, websites, or systems in exchange for monetary rewards. Companies run bug bounty programs to leverage ethical hackers' skills in identifying potential threats before malicious hackers can exploit them. Bug bounty hunters typically work as independent security researchers and submit vulnerability reports to organizations through platforms like HackerOne, Bugcrowd, or Synack. Payments vary based on the severity of the discovered flaw, with critical vulnerabilities earning the highest rewards.
What are the typical daily responsibilities of someone participating in bug bounty programs?
As a bug bounty professional, your daily activities often involve researching target applications, actively probing for vulnerabilities using automated tools and manual techniques, and documenting your findings in detailed reports. You may spend significant time reproducing and validating security issues before responsibly disclosing them to the organization via official bug bounty platforms. Collaboration is usually asynchronous, with occasional interactions with in-house security teams for clarification or follow-up on reported issues. Managing your workflow and keeping up with evolving security trends are also essential parts of the job, ensuring your findings remain thorough and relevant.
What are the key skills and qualifications needed to thrive in the bug bounty position, and why are they important?
To thrive as a Bug Bounty professional, you need a strong understanding of web application security, programming languages, and vulnerability assessment methodologies. Familiarity with tools such as Burp Suite, OWASP ZAP, and various penetration testing frameworks, as well as certifications like OSCP or CEH, is highly valued. Persistence, attention to detail, and effective written communication are essential soft skills in this role. These competencies enable professionals to discover, document, and report security flaws accurately, helping organizations improve their cyber defenses.
Can a bug bounty be a career?
How to become a bug bounty?
What cities are hiring for Bug Bounty jobs?
Cities with the most Bug Bounty job openings:
What are the most commonly searched types of Bug Bounty jobs?
The most popular types of Bug Bounty jobs are:
What states have the most Bug Bounty jobs?
States with the most job openings for Bug Bounty jobs include:
What job categories do people searching Bug Bounty jobs look for?
The top searched job categories for Bug Bounty jobs are:

Bug Bounty Security Researcher
On-site, Remote
Contractor
Posted 9 days ago
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Bug Bounty Security Researcher based in Netherlands.
This is an exciting security research opportunity for a skilled professional passionate about discovering vulnerabilities and strengthening real-world application security.
You will investigate software applications, systems, and networks to uncover security weaknesses before they can be exploited maliciously.
The role combines offensive security research, creative attack development, vulnerability exploitation, and detailed technical reporting.
You will work across web, mobile, and network security environments while participating in private and public bug bounty programs.
Your findings will directly contribute to improving security products and services and protecting customers against emerging threats.
The position offers flexibility to work independently, explore challenging targets, and be rewarded for high-impact vulnerabilities.
This opportunity is ideal for a curious and analytical security researcher who enjoys continuous learning and responsible vulnerability disclosure.
- Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.
- Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.
- Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.
- Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.
- Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.
- Participate in ongoing bug bounty programs and private security research engagements.
- Share security findings and insights that can help improve products, services, and overall vulnerability management practices.
- Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.
- Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.
Requirements
- At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.
- Strong understanding of computer systems, networks, web applications, and software security.
- Practical knowledge of offensive security methodologies and vulnerability discovery techniques.
- Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
- Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.
- Experience participating in bug bounty programs and applying responsible disclosure practices.
- Strong analytical, investigative, and problem-solving abilities.
- Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.
- Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.
- 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.
- A recognized public bug bounty profile with awarded vulnerability reports is preferred.
- Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.
- Strong sense of responsibility and commitment to ethical security research.
Benefits
- Flexible freelance engagement allowing you to work according to your own schedule.
- Bounty awards for valid and accepted vulnerability reports.
- Weekly payments for valid reports following successful triage.
- Recognition for high-quality submissions through leaderboards both on and outside the platform.
- Opportunities to perform real-world penetration testing across web application, mobile, and network security.
- Access to private and exclusive bug bounty programs.
- Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.
- Collaborative, empathy-led security culture focused on improving internet security.
- Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.