1

Bug Bounty Manager Jobs in Raleigh, NC (NOW HIRING)

Vulnerability management programs * Red teaming exercises * Bug bounty and responsible disclosure programs * Software supply chain security controls * SBOM management * Secure CI/CD pipelines

Bug Bounty Manager information

What is a bug bounty manager?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What does a bug bounty manager do?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a bug bounty manager?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

What are the most commonly searched types of Bug Bounty jobs in Raleigh, NC?

The most popular types of Bug Bounty jobs in Raleigh, NC are:

What job categories do people searching Bug Bounty Manager jobs in Raleigh, NC look for?

The top searched job categories for Bug Bounty Manager jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Bug Bounty Manager jobs?

Cities near Raleigh, NC with the most Bug Bounty Manager job openings:

Vice President, Product Security

Raleigh, NC • On-site

Qualys
Network Security • 1 - 5K employees

Other

Posted 5 days ago


Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Qualifications

Leadership & Executive Management

  • 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams.

  • Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.

  • Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.

  • Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.

  • Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.

  • Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.

  • Experienceparticipatingin M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.

Product Security & Secure Engineering

  • Deepexpertisein product security, application security, cloud security,DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices.

  • Demonstrated experience implementing and scaling:

  • Security-by-design principles

  • Threat modeling frameworks

  • Secure coding standards

  • Vulnerability management programs

  • Red teaming exercises

  • Bug bounty and responsible disclosure programs

  • Software supply chain security controls

  • SBOM management

  • Secure CI/CD pipelines

  • Container and Kubernetes security

  • Extensive knowledge of modern authentication and identity architectures including:

  • Zero Trust

  • OAuth2

  • OpenID Connect

  • SAML

  • PKI

  • Hardware-backed cryptography

  • Secrets management

  • PAM solutions

  • Deep understanding of modern security frameworks including:

  • NIST Cybersecurity Framework

  • NIST SP 800-53

  • NIST SP 800-171

  • NIST SP 800-218 (SSDF)

  • CIS Controls

  • OWASP Top 10

  • OWASP ASVS

  • SOC 2

  • ISO 27001

Federal Compliance & Government Security Experience

FedRAMP

  • 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.

  • Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.

  • Extensive experience working directly with:

  • Federal Agencies

  • Joint Authorization Board (JAB) stakeholders

  • Third Party Assessment Organizations (3PAOs)

  • Authorizing Officials

  • Government security assessors

  • Deep knowledge of:

  • NIST SP 800-53 Rev. 5

  • FedRAMP Continuous Monitoring

  • POA&M management

  • Significant Change Requests

  • Annual Assessments

  • Vulnerability remediation requirements

  • Configuration management controls

  • Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.

CMMC & DoD Cloud Requirements

  • Hands-on experience implementing and managing environments aligned to:

  • CMMC Level 2 requirements

  • NIST SP 800-171

  • DFARS 252.204-7012

  • DFARS 252.204-7019

  • DFARS 252.204-7020

  • DFARS 252.204-7021

  • Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.

  • Demonstrated knowledge and practical experience supporting:

  • DoD Impact Level 4 (IL4)

  • DoD Impact Level 5 (IL5)

  • DoD Impact Level 6 (IL6)

  • Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.

  • Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.

NIAP & Common Criteria

  • Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.

  • Strong understanding of:

  • Common Criteria Evaluation and Validation Scheme (CCEVS)

  • Protection Profiles

  • Security Targets

  • Evaluation Assurance Levels (EAL)

  • NIAP product certification lifecycle

  • Experience working with accredited testing laboratories and certification authorities to achieve andmaintainproduct certifications.

Multi-Cloud Security &HyperscalerExpertise

  • 15+ years of experience designing and securing cloud-native SaaS platformsoperatingat enterprise scale.

  • Demonstrated architecture and operationalexpertiseacross multiple hyperscale cloud service providers including:

Amazon Web Services (AWS)

  • Experience securing AWS environmentsleveraging:

  • Organizations

  • IAM

  • KMS

  • CloudTrail

  • GuardDuty

  • Security Hub

  • Control Tower

  • ECS/EKS

  • Native compliance controls

Microsoft Azure

  • Experience securing Azure environmentsutilizing:

  • Entra ID

  • Azure Policy

  • Defender for Cloud

  • Key Vault

  • Azure Monitor

  • Microsoft Sentinel

  • AKS

  • Landing Zone architectures

Google Cloud Platform (GCP)

  • Experience designing secure GCP architecturesleveraging:

  • Cloud IAM

  • Security Command Center

  • Cloud KMS

  • Anthos

  • Chronicle

  • Organization Policies

  • GKE security controls

Oracle Cloud Infrastructure (OCI)

  • Experience securing OCI environments including:

  • OCI IAM

  • OCI Vault

  • Cloud Guard

  • Security Zones

  • OCI Logging

  • OCI Container Engine for Kubernetes (OKE)

  • Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments.

  • Demonstratedtrack recordimplementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI.

Preferred Qualifications

  • CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications.

  • Prior experience serving as:

  • VP Product Security

  • Head of Product Security

  • Chief Product Security Officer

  • Distinguished Security Architect

  • Senior Security Executive within a cybersecurity or cloud technology company.

  • Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees.

  • Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies.

Qualys is an Equal Opportunity Employer, please see our EEO policy.