About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
About the team In this role, you'll join Stripe's Vulnerability Management team, whose mission is ... The bug bounty program is an important pillar of this mission, acting as a critical line of defense ...
Technical Program Manager, Bug Bounty
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
Technical Program Manager, Bug Bounty
Seattle, WA · On-site
$146K - $190K/yr
Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...
$78.28 - $104.75/hr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
New
$78.28 - $104.75/hr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
New
$78.28 - $104.75/hr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
New
$78.28 - $104.75/hr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
New
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents ...
Product Security Engineer
Lehi, UT · On-site
$67.61 - $84.51/hr
Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and ... Communicate with external researchers to request clarifications, provide status updates, and manage ...
Product Security Engineer
Lehi, UT · On-site
$67.61 - $84.51/hr
Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and ... Communicate with external researchers to request clarifications, provide status updates, and manage ...
Manager, Offensive Product Cybersecurity & PSOC
Milford, MI · On-site
$150 - $190/hr
Coordinate with third‑party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
New
Manager, Offensive Product Cybersecurity & PSOC
Milford, MI · On-site
$150 - $190/hr
Coordinate with third‑party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
New
Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse ...
Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse ...
Lead the end to end technical onboarding and configuration of Bug Bounty, Vulnerability Disclosure ... Collaborate closely with the Customer Relationship Managers and sales teams to align technical ...
Lead the end to end technical onboarding and configuration of Bug Bounty, Vulnerability Disclosure ... Collaborate closely with the Customer Relationship Managers and sales teams to align technical ...
Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse ...
Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse ...
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Senior Technical Program Manager, Security
Foster City, CA · On-site
$140 - $200/hr
Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends. * Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure ...
New
Senior Technical Program Manager, Security
Foster City, CA · On-site
$140 - $200/hr
Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends. * Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure ...
New
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
$180K - $325K/yr
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Foster City, CA · On-site
$180K - $325K/yr
Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. * Independently validate, reproduce ...
Lead the end to end technical onboarding and configuration of Bug Bounty, Vulnerability Disclosure ... Collaborate closely with the Customer Relationship Managers and sales teams to align technical ...
Lead the end to end technical onboarding and configuration of Bug Bounty, Vulnerability Disclosure ... Collaborate closely with the Customer Relationship Managers and sales teams to align technical ...
Senior Security Engineer
Los Angeles, CA · On-site
$123K - $169K/yr
Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and ...
Senior Security Engineer
Los Angeles, CA · On-site
$123K - $169K/yr
Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and ...
Bug Bounty Manager information
What is a bug bounty manager?
What does a bug bounty manager do?
What are the key skills and qualifications needed to thrive as a bug bounty manager?
What is the difference between Bug Bounty Manager vs Security Analyst?
| Aspect | Bug Bounty Manager | Security Analyst |
|---|---|---|
| Required Credentials | Certifications like OSCP, CEH, or CISSP; experience in bug bounty programs | Certifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols |
| Work Environment | Focus on managing bug bounty programs, coordinating with researchers, and analyzing reports | Monitoring security systems, conducting vulnerability assessments, and incident response |
| Employer & Industry Usage | Tech companies, cybersecurity firms, organizations running bug bounty programs | Corporate security teams, government agencies, consulting firms |
The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.
What cities are hiring for Bug Bounty Manager jobs?
Cities with the most Bug Bounty Manager job openings:
What are the most commonly searched types of Bug Bounty jobs?
The most popular types of Bug Bounty jobs are:
What states have the most Bug Bounty Manager jobs?
States with the most job openings for Bug Bounty Manager jobs include:
What job categories do people searching Bug Bounty Manager jobs look for?
The top searched job categories for Bug Bounty Manager jobs are:

Job description
Stripe is a financial infrastructure platform for businesses. Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the teamIn this role, you'll join Stripe's Vulnerability Management team, whose mission is to "Surface vulnerabilities at scale across Stripe." Our vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission, acting as a critical line of defense in Stripe's security "immune system."
What you'll doWe seek a highly technical and detail-oriented Security Analyst to join our team, focusing on the front lines of bug bounty triage and researcher engagement. In this role, you'll be responsible for the end-to-end lifecycle of security vulnerability reports from our bug bounty program. You'll own the overall effectiveness of Stripe's bug bounty program with autonomy to implement continuous improvements (e.g., researcher campaigns, scoring transparency).
You'll play a key role in understanding the root cause of vulnerabilities, coordinating timely resolutions, and directly impacting the security posture of Stripe's products. A core aspect of this role is developing a deep understanding of Stripe and acquired company products, assets, and their configuration to effectively assess and prioritize vulnerabilities.
Responsibilities- Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program
- Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers
- Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies
- Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders
- Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation
- Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives
- Provide tactical support for vulnerability management triage processes to augment the team as needed
- Prepare and implement improvements to the overall bug bounty program
- Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements- Proven ability to follow bug reports and accurately triage security vulnerabilities
- Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs)
- Competent in offensive security tools (e.g., Burp Suite, custom scripting)
- Ability to think like an attacker to understand the impact of vulnerabilities
- Proficient in clear communication, conveying technical concepts to various stakeholders
- Experience in one of the following areas
- Bug bounty program or triaging security vulnerability reports
- Knowledge of Stripe products and general security expertise
- Experience in technical support, operations, or similar roles with technical systems exposure
- Prior participation in or experience with bug bounty programs
- Experience analyzing source code for security vulnerabilities
- Proficiency in scripting languages (e.g., Python, Ruby) for automation
- Familiarity with cloud-based services (e.g., AWS, GCP)
- Certifications such as OSWA or BSCP
About Stripe
Sourced by ZipRecruiter
Industry
Software development
Company size
1,001 - 5,000 Employees
Headquarters location
San Francisco, CA, US
Year founded
2010