1

Bug Bounty Manager Jobs in Oregon (NOW HIRING)

Vulnerability Management : Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security ...

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

... key management, passwordless authentication, m2m authentication, sandboxing and compute/network ... Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ...

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

Staff Security Engineer, Application Security

OR · On-site +1

$210K - $260K/yr

  • Retirement

  • PTO

Own key security domains such as vulnerability management, application security, API security, and ... Experience with bug bounty programs and penetration testing * Security certifications such as CISSP ...

Senior Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a ... Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ...

Head of Security Engineering

OR · On-site +1

  • Medical

  • Dental

  • Vision

  • Retirement

Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep ... Experience setting strategy, managing roadmaps, and delivering measurable security outcomes across ...

Bug Bounty Manager information

What is a bug bounty manager?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What does a bug bounty manager do?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a bug bounty manager?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

What are the most commonly searched types of Bug Bounty jobs in Oregon?

The most popular types of Bug Bounty jobs in Oregon are:

What are popular job titles related to Bug Bounty Manager jobs in Oregon?

For Bug Bounty Manager jobs in Oregon, the most frequently searched job titles are:

What cities in Oregon are hiring for Bug Bounty Manager jobs?

Cities in Oregon with the most Bug Bounty Manager job openings:

Senior Product Security Engineer

Tines

OR • On-site, Remote

Full-time

Re-posted 16 days ago


Job description

The Role

We're seeking a Senior Product Security Engineer who is passionate about building and scaling robust security programs in an AI-forward engineering environment. Reporting to our Head of IT Operations & Information Security, you'll lead efforts to mature our product security initiatives at a pivotal moment of product expansion, ensuring security keeps pace as our developers increasingly leverage AI in their workflows.

A core part of this role is using AI and automation as force multipliers, building security tooling, guardrails, and review processes that scale to match the velocity of AI-assisted development across our engineering org.

This position can be based remotely in the United States.

Key Responsibilities
  • Product Security Leadership: Partner with product and engineering teams to integrate security throughout the development lifecycle and drive security initiatives across our stack.
  • AI-Augmented Security: Leverage AI and automation to scale product security coverage, matching the pace of AI-assisted development across engineering.
  • Security Architecture: Design and implement security controls and architecture that scale with our growing product portfolio.
  • Threat Modeling & Risk Assessment: Conduct comprehensive security reviews and threat modeling to identify and mitigate potential vulnerabilities, including risks introduced by AI-generated code and AI-powered features.
  • Vulnerability Management: Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts.
  • Security Automation: Develop and implement automated security testing, monitoring, and response capabilities, using Tines itself, plus AI-driven tooling, to eliminate manual toil.
  • Security Incident Response: Serve as an incident responder during security events and lead post-incident reviews.
  • Security Education: Champion security awareness and provide technical guidance to engineering teams, including best practices for secure AI-assisted development.
Qualifications
  • 8+ years of experience in application or product security roles, with demonstrated expertise in securing cloud-native applications.
  • Strong understanding of modern application security principles, OWASP Top 10, and secure SDLC practices.
  • Experience leveraging AI and automation to scale security programs (e.g., LLM-assisted code review, automated triage, agentic security workflows).
  • Experience with cloud security (AWS preferred) and securing containerized environments (Docker, Kubernetes).
  • Proficiency in modern programming languages; experience with Ruby, TypeScript, and/or Rust is highly desirable.
  • Knowledge of security testing methodologies and tools (SAST, DAST, SCA).
  • Experience with CI/CD security integration and DevSecOps practices.
  • Strong incident response skills and experience participating in on-call rotations.
  • Excellent communication skills with ability to translate complex security concepts to diverse audiences.
  • Self-motivated with exceptional analytical thinking and problem-solving abilities.
Nice to Haves
  • Experience securing AI/ML systems and LLM-powered features (prompt injection, model abuse, data leakage, agentic system risks).
  • Familiarity with LLM red-teaming, AI threat modeling frameworks (e.g., MITRE ATLAS, OWASP LLM Top 10), and emerging AI security standards.
  • Hands-on experience building agentic or automated security workflows (using Tines or similar platforms).
  • Contributions to open-source security tooling or active participation in the security research community (CVEs, conference talks, published research).
  • Experience designing secure-by-default developer platforms, paved roads, or golden paths for engineering teams.
  • Background in bug bounty triage at scale, or running a public VDP/bug bounty program.
  • Familiarity with multi-tenant SaaS security challenges (tenant isolation, authz models, data segregation).
  • Experience supporting FedRAMP (Moderate/High) and/or DoD Impact Level (IL4/IL5/IL6) environments.
  • Prior experience at a high-growth startup launching new products or expanding into new product lines.

Target Annual Compensation: $218-$235k + equity

Applicants for this opportunity must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.