1

Bug Bounty Manager Jobs in Oregon (NOW HIRING)

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

... key management, passwordless authentication, m2m authentication, sandboxing and compute/network ... Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ...

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

IAM, workload identity, secrets management, security services (e.g., GCP Security Command Center ... Background in security research or offensive security (bug bounty, CTF, penetration testing)

Own key security domains such as vulnerability management, application security, API security, and ... Experience with bug bounty programs and penetration testing * Security certifications such as CISSP ...

Senior Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a ... Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ...

Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep ... Experience setting strategy, managing roadmaps, and delivering measurable security outcomes across ...

Bug Bounty Manager information

What is a bug bounty manager?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What does a bug bounty manager do?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a bug bounty manager?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

What are the most commonly searched types of Bug Bounty jobs in Oregon?

The most popular types of Bug Bounty jobs in Oregon are:

What are popular job titles related to Bug Bounty Manager jobs in Oregon?

For Bug Bounty Manager jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Bug Bounty Manager jobs in Oregon look for?

The top searched job categories for Bug Bounty Manager jobs in Oregon are:

What cities in Oregon are hiring for Bug Bounty Manager jobs?

Cities in Oregon with the most Bug Bounty Manager job openings:

Senior Product Security Engineer

OR • On-site, Remote

ClickHouse
Software Development • 51 - 200 employees

$114K - $156K/yr

Full-time

Re-posted 1 hour ago


Job description

About the team 

The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services. 

What you will do:

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL)
  • Nurture the engineering - security relationship, identify and implement process and technology improvements
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

What you bring along:

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium, Crossplane
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Significant development and automation experience, ability to work with C++ code preferred
  • Security as code mindset, with focus on solving problems with automation and scale in mind

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)