1

Bug Bounty Manager Jobs in Utah (NOW HIRING)

Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and ... Communicate with external researchers to request clarifications, provide status updates, and manage ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Bug Bounty Manager information

What is a bug bounty manager?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What does a bug bounty manager do?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a bug bounty manager?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

What are the most commonly searched types of Bug Bounty jobs in Utah?

The most popular types of Bug Bounty jobs in Utah are:

What cities in Utah are hiring for Bug Bounty Manager jobs?

Cities in Utah with the most Bug Bounty Manager job openings:

$67.61 - $84.51/hr

Contractor

Medical, Dental, Vision, Retirement

Re-posted 26 days ago


Job description

Product Security Engineer
Full-time
Lehi, UT

You’ll be joining Adobe on a contract opportunity, employed through NextDeavor

 
Benefits You'll Love

NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave eligibility is contingent on state of residence Optional 401k Plan (excludes employer match) Opportunity to get your foot in the door at a well-established corporation, with potential for extended or permanent full-time employment

Become a Key Player as a Product Security Engineer

You will lead triage and validation of external vulnerability reports for the client's products, ensuring timely, accurate resolution and clear researcher communications. You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a team member on leave.

Here's How You'll Make an Impact on the Team
  • Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and scope.
  • Assign CVSS scores and severity ratings following internal guidelines and industry standards.
  • Reproduce proof-of-concept exploits across web, API, and mobile surfaces to validate reports.
  • Communicate with external researchers to request clarifications, provide status updates, and manage expectations.
  • Coordinate confirmed vulnerabilities with product engineering teams for remediation.
  • Identify duplicates, out-of-scope, or informational reports and close them with clear explanations.
  • Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
  • Flag systemic or critical findings to the Bug Bounty team for escalation.
Here's What You'll Need to Be Successful in This Role
  • 3+ years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
  • Strong understanding of CVSS v3.1 and hands-on experience applying it to real-world vulnerabilities.
  • Proficiency with common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
  • Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts.
  • Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and responsible disclosure processes.
  • Solid written communication skills for clear, constructive responses to external researchers.
  • Familiarity with attacker techniques against LLM systems and generative AI products.
  • Knowledge of OWASP Top 10 vulnerabilities and mitigation techniques.
Here's What Else Might Help You Out
  • Experience with cloud environments (AWS, Azure, GCP) and API security testing.
  • Hands-on penetration testing experience for AI/ML and LLM-powered products, including chat interfaces and inference APIs.
  • Prior participation in bug bounty programs as a researcher.
  • Familiarity with CWE taxonomy and CVE assignment processes.
  • Background working within a large enterprise or SaaS security organization.
Pay Range

$67.61 - $84.51/hour

Ready to Make Your Mark?

This role may fill quickly. Submit your resume to be considered.

Apply with Pioneers here