1

Bug Bounty Manager Jobs in Raleigh, NC (NOW HIRING)

Bug Bounty Manager information

What does a typical week look like for a Bug Bounty Manager in terms of responsibilities and collaboration?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a Bug Bounty Manager, and why are they important?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What are Bug Bounty Managers?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

What are the most commonly searched types of Bug Bounty jobs in Raleigh, NC? The most popular types of Bug Bounty jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Bug Bounty Manager jobs? Cities near Raleigh, NC with the most Bug Bounty Manager job openings:

Global Security PSIRT Engineer

NetApp, Inc.

Morrisville, NC • On-site

Full-time

Medical, Life, Retirement, PTO

Re-posted 5 days ago


NetApp rating

9.4

Company rating: 9.4 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

2nd of 488 rated business services


Job description

Job Summary
NetApp is looking for a skilled PSIRT Engineer (IC4) to join our Global Product Security Incident Response Team.
In this role, you will independently handle complex security vulnerabilities across NetApp's storage, cloud, and data management products. You will triage reports, perform technical analysis, drive fixes, and coordinate responsible disclosure.
As an IC4 engineer, you will work on high-impact issues, mentor junior team members, and help mature NetApp's PSIRT processes in alignment with ISO/IEC 30111, ISO/IEC 29147, and FIRST best practices. This is a technical, customer-focused role that directly protects NetApp customers worldwide
Job Responsibilities
Triage, verify, and conduct in-depth technical analysis of vulnerability reports from external researchers, customers, internal teams, and security tools.
Reproduce vulnerabilities in lab environments and assess risk using CVSS (v3.1/v4.0) along with NetApp-specific business and customer context.
Collaborate with engineering teams to drive root cause analysis, develop fixes, mitigations, and workarounds, and validate their effectiveness.
Manage the full vulnerability lifecycle, including embargo handling, coordinated disclosure (CVD), CVE-ID requests, and publication of Security Advisories.
Work with external stakeholders such as security researchers, CERT/CC, and other vendors for multi-party coordination.
Support proactive vulnerability monitoring, threat intelligence, third-party component tracking, and integration with the Secure Development Lifecycle (SDL).
Create clear technical documentation, customer advisories, and leadership briefings.
Mentor junior PSIRT engineers and participate in team on-call rotation.
Contribute to process improvements, tooling, metrics, and PSIRT maturity initiatives.
Job Requirements
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent experience).
5+ years of experience in security engineering, vulnerability management, incident response, or product security.
Strong technical knowledge of operating systems (Linux/Unix), networking, storage systems, and cloud platforms (AWS, Azure, GCP).
Hands-on experience reproducing and analyzing security vulnerabilities.
Solid understanding of CVSS, CVE, CWE, responsible disclosure, and coordinated vulnerability disclosure practices.
Excellent written and verbal communication skills - able to explain complex issues clearly to both technical and non-technical audiences.
Proven ability to work independently and collaboratively in a global team environment.
Preferred Qualifications
Previous experience working in a PSIRT, Product Security, or Vulnerability Management program.
Familiarity with NetApp products (e.g., ONTAP, StorageGRID) or enterprise storage/data management technologies.
Scripting and automation skills (Python, Bash, PowerShell).
Knowledge of SBOMs, software composition analysis, and supply chain security.
Industry certifications such as CISSP, OSCP, or GIAC.
Experience with bug bounty platforms (e.g., HackerOne).
Education
IC - Typically requires a minimum of 8 years of related experience.Mgr & Exec - Typically requires a minimum of 6 years of related experience.
Compensation:
The target salary range for this position is 147,900 - 220,000 USD. The salary offered will be determined by the candidate's location, qualifications, experience, and education and may be outside of this range. The range is based on 'On Target Earnings' (OTE) representing the total potential earnings, which is the sum of the base salary and potential commission earned when performance targets are achieved. Final compensation packages are competitive and in line with industry standards, reflecting a variety of factors, and include a comprehensive benefits package. This may cover Health Insurance, Life Insurance, Retirement or Pension Plans, Paid Time Off, various Leave options, employee stock purchase plan, and/or restricted stocks (RSU's). These offerings are subject to regional variations and governed by local laws, regulations, and company policies. We will provide detailed information about the specific benefits for your region during the recruitment process.

What NetApp employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom