... management programs. You will own the tooling that continuously tests our environment - bug bounty, agentic red team, CSPM, and vulnerability scanners - turn the output of those platforms into a ...
... management programs. You will own the tooling that continuously tests our environment - bug bounty, agentic red team, CSPM, and vulnerability scanners - turn the output of those platforms into a ...
Infrastructure Security Engineer
Charleston, WV · On-site
$132K/yr
... management programs. You will own the tooling that continuously tests our environment - bug bounty, agentic red team, CSPM, and vulnerability scanners - turn the output of those platforms into a ...
Infrastructure Security Engineer
Charleston, WV · On-site
$132K/yr
... management programs. You will own the tooling that continuously tests our environment - bug bounty, agentic red team, CSPM, and vulnerability scanners - turn the output of those platforms into a ...
Senior Product Security Engineer
Austin, TX · On-site
$190 - $240/hr
Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug ... Proven track record of managing, routing, and driving the remediation of vulnerabilities across ...
New
Senior Product Security Engineer
Austin, TX · On-site
$190 - $240/hr
Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug ... Proven track record of managing, routing, and driving the remediation of vulnerabilities across ...
New
Senior Security Engineer - Product Security
Evans, GA · On-site
$96K - $132K/yr
This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk ...
Posted today
Senior Security Engineer - Product Security
Evans, GA · On-site
$96K - $132K/yr
This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk ...
Posted today
Senior Security Engineer - Product Security
$106K - $146K/yr
This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk ...
Posted today
Senior Security Engineer - Product Security
$106K - $146K/yr
This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk ...
Posted today
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$320K - $485K/yr
Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale * Background building security automation or developer-facing security ...
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$320K - $485K/yr
Prior ownership of a bug bounty program, vulnerability disclosure program, or vulnerability-management infrastructure at scale * Background building security automation or developer-facing security ...
Manager, Offensive Product Cybersecurity & PSOC
Warren, MI · On-site
$104K - $140K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
Manager, Offensive Product Cybersecurity & PSOC
Warren, MI · On-site
$104K - $140K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
Manager, Offensive Product Cybersecurity & PSOC
$97K - $131K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
Manager, Offensive Product Cybersecurity & PSOC
$97K - $131K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
$208 - $312/hr
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
New
$208 - $312/hr
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
New
Manager, Offensive Product Cybersecurity & PSOC
$104K - $140K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
Manager, Offensive Product Cybersecurity & PSOC
$104K - $140K/yr
Coordinate with third-party security researchers through the bug bounty program and lead PSIRT ... Ability to manage multiple complex projects simultaneously with defined milestones and success ...
Product Security Engineer
San Francisco, CA · On-site
$208 - $312/hr
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
Product Security Engineer
San Francisco, CA · On-site
$208 - $312/hr
Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...
Lead the overall Security Product Engineering, Bug Bounty and Mythos era Vulnerability Management direction and roadmap execution. * Coach and mentor highly skilled engineers as a "player-coach ...
Lead the overall Security Product Engineering, Bug Bounty and Mythos era Vulnerability Management direction and roadmap execution. * Coach and mentor highly skilled engineers as a "player-coach ...
Senior Protocol Engineer (Verification)
Manhattan, NY · On-site
$150 - $190/hr
... audits to bug bounty program management. As the protocol team scales and takes on more complexity, this person reduces risk and shortens audit cycles so the team can move with confidence.
New
Senior Protocol Engineer (Verification)
Manhattan, NY · On-site
$150 - $190/hr
... audits to bug bounty program management. As the protocol team scales and takes on more complexity, this person reduces risk and shortens audit cycles so the team can move with confidence.
New
Senior Product Security Engineer
OR · On-site +1
Vulnerability Management : Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security ...
Senior Product Security Engineer
OR · On-site +1
Vulnerability Management : Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security ...
$150 - $170/hr
... management programs. You will own the tooling that continuously tests our environment -- bug bounty, agentic red team, CSPM, and vulnerability scanners -- turn the output of those platforms into a ...
New
$150 - $170/hr
... management programs. You will own the tooling that continuously tests our environment -- bug bounty, agentic red team, CSPM, and vulnerability scanners -- turn the output of those platforms into a ...
New
Engineer, Production Engineering
San Francisco, CA · On-site
$130 - $150/hr
Penetration Testing & Bug Bounty: Manage our HackerOne engagement -- coordinating pentests, triaging incoming bug bounty reports, and driving remediation. * Product Security: Audit application code ...
Engineer, Production Engineering
San Francisco, CA · On-site
$130 - $150/hr
Penetration Testing & Bug Bounty: Manage our HackerOne engagement -- coordinating pentests, triaging incoming bug bounty reports, and driving remediation. * Product Security: Audit application code ...
You understand how different test types (vulnerability scanning, penetration testing, bug bounty ... Experience building or product-managing systems that use ML for entity resolution, deduplication ...
You understand how different test types (vulnerability scanning, penetration testing, bug bounty ... Experience building or product-managing systems that use ML for entity resolution, deduplication ...
Member of Technical Staff (Software Engineer, Security)
New York, NY · On-site +1
$220K - $405K/yr
Experience operating or contributing to bug bounty or vulnerability management programs is a plus. * Familiarity with cloud infrastructure (AWS preferred) and modern SaaS environments. * Ability to ...
Member of Technical Staff (Software Engineer, Security)
New York, NY · On-site +1
$220K - $405K/yr
Experience operating or contributing to bug bounty or vulnerability management programs is a plus. * Familiarity with cloud infrastructure (AWS preferred) and modern SaaS environments. * Ability to ...
Job Summary We are looking for an innovative Staff Product Manager, AI & Data to define the vision ... tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized ...
Job Summary We are looking for an innovative Staff Product Manager, AI & Data to define the vision ... tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized ...
Senior App Security Engineer -- Build Secure Web & Mobile
Redmond, WA · On-site
$168 - $230/hr
The role involves auditing applications, designing security solutions, and managing bug bounty submissions. Ideal candidates have a Bachelor's degree in computer science and at least 5 years of ...
New
Senior App Security Engineer -- Build Secure Web & Mobile
Redmond, WA · On-site
$168 - $230/hr
The role involves auditing applications, designing security solutions, and managing bug bounty submissions. Ideal candidates have a Bachelor's degree in computer science and at least 5 years of ...
New
Bug Bounty Manager information
What is a bug bounty manager?
What does a bug bounty manager do?
What are the key skills and qualifications needed to thrive as a bug bounty manager?
What is the difference between Bug Bounty Manager vs Security Analyst?
| Aspect | Bug Bounty Manager | Security Analyst |
|---|---|---|
| Required Credentials | Certifications like OSCP, CEH, or CISSP; experience in bug bounty programs | Certifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols |
| Work Environment | Focus on managing bug bounty programs, coordinating with researchers, and analyzing reports | Monitoring security systems, conducting vulnerability assessments, and incident response |
| Employer & Industry Usage | Tech companies, cybersecurity firms, organizations running bug bounty programs | Corporate security teams, government agencies, consulting firms |
The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.
What cities are hiring for Bug Bounty Manager jobs?
Cities with the most Bug Bounty Manager job openings:
What are the most commonly searched types of Bug Bounty jobs?
The most popular types of Bug Bounty jobs are:
What states have the most Bug Bounty Manager jobs?
States with the most job openings for Bug Bounty Manager jobs include:
What job categories do people searching Bug Bounty Manager jobs look for?
The top searched job categories for Bug Bounty Manager jobs are:

$132K/yr
Full-time
Medical, Dental, Vision, PTO
Posted 7 days ago
Job description
About Us
At Cast & Crew, we've empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies - we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production's best ally every step of the way.#OneCastOneCrew
Position OverviewWe are looking for an Infrastructure Security Engineer to run the operational core of our offensive and vulnerability management programs. You will own the tooling that continuously tests our environment - bug bounty, agentic red team, CSPM, and vulnerability scanners - turn the output of those platforms into a prioritized, de-duplicated set of real issues, and drive them to verified closure with engineering and infrastructure teams. This is a hands-on, highly cross-functional role for someone who is as comfortable validating an exploit as they are chasing a fix to completion.
We are also looking for someone who is genuinely curious and learns fast. Our security stack changes quickly, and a meaningful part of this role is exploring, testing, and deploying emerging security products - including tooling built on the latest AI capabilities - evaluating whether they actually work in our environment, and putting the ones that do into production.
Core ResponsibilitiesBug Bounty ProgramOversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.
Triage inbound submissions: reproduce and validate findings, de-duplicate against known issues, assign severity, and reject out-of-scope or invalid reports with clear rationale.
Make and defend bounty award decisions in coordination with the platform provider and Security leadership.
Route confirmed findings to the owning engineering or infrastructure team, track them to closure, and verify fixes before the report is closed.
Use recurring submission patterns to drive systemic fixes, scope adjustments, and secure-development feedback rather than one-off patches.
Manage and operate enterprise vulnerability scanners across cloud, on-premise, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps.
Configure, tune, and maintain scan policies, credentialed scanning, authenticated checks, and scan schedules to maximize signal and minimize disruption.
Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence).
Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-scan or manual validation.
Track remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team.
Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences.
Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching when critical vulnerabilities arise.
Manage and operate the CSPM platform across our multi-cloud environment, including onboarding new accounts, subscriptions, and projects.
Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable.
Drive remediation of misconfigurations with cloud and platform owners, and verify that fixes hold over time.
Enforce least-privilege access principles and audit cloud permissions, IAM policies, security groups, SCPs, and guardrails on a recurring basis.
Support secure architecture reviews for new cloud infrastructure and services.
Manage and operate the agentic red-team pentesting platform, including target scoping, scheduling, credentials, and environment onboarding.
Define and enforce rules of engagement and safety guardrails so that automated testing does not disrupt production systems.
Validate platform output, eliminate false positives, and translate confirmed attack paths into concrete, owner-assigned remediation items.
Feed results into the same triage, prioritization, and verification workflow used for scanner and bug bounty findings so there is one prioritized view of risk.
Coordinate with third-party penetration testers and use platform coverage to focus manual testing where it adds the most value.
Research, pilot, and benchmark emerging security products, including AI-driven and agentic tooling, against real problems in our environment rather than vendor demos.
Run structured proofs of concept: define success criteria up front, test against known findings, and make a clear recommendation to adopt, defer, or reject.
Deploy and integrate selected tooling into existing workflows and ticketing, and own it operationally once it is in production.
Automate repetitive triage, enrichment, and reporting work so that engineering time goes to remediation rather than data handling.
Support enterprise network security infrastructure including firewalls, IDS/IPS, proxies, VPNs, and DDoS mitigation.
Perform firewall rule reviews and access control audits to reduce attack surface.
Investigate anomalous network activity surfaced by security tooling and escalate to incident response as needed.
3-5 years of experience in infrastructure, network, or cloud security roles.
Experience running or supporting an enterprise vulnerability management program end-to-end, from scanner operation through verified remediation.
Demonstrated ability to triage security findings: reproduce issues, judge real-world exploitability, de-duplicate, and prioritize against business context rather than raw severity scores.
Deep, practical understanding of common vulnerability classes and how they are actually exploited - remote code execution, injection, cross-site scripting, SSRF, insecure deserialization, authentication and authorization bypasses, and denial-of-service and DDoS techniques - sufficient to assess real exploitability rather than defer to a scanner score.
Hands-on proficiency with security testing tooling, including Burp Suite for web application testing and Postman for API testing, along with comparable intercepting proxies and fuzzing tools.
Working coding ability, primarily Python and shell scripting, sufficient to automate triage and reporting, parse and enrich findings, build integrations between security platforms, and write or adapt proof-of-concept code to validate a finding.
Hands-on experience securing at least one major cloud platform (AWS, Azure, or GCP), including operating or responding to CSPM tooling.
Solid understanding of network protocols (TCP/IP, DNS, TLS) and perimeter security technologies.
Familiarity with security frameworks and standards (NIST CSF, CIS Benchmarks, ISO 27001) and the ability to translate control requirements into actionable technical configurations, including gathering, maintaining, and presenting evidence to support audit and assessment activities.
Strong written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and to hold remediation owners accountable without escalating every disagreement.
Demonstrated curiosity and speed of learning: a track record of picking up unfamiliar tooling, evaluating new security products, and getting them into production use without extensive hand-holding.
Interest in applying emerging AI capabilities to security operations, and the judgment to distinguish tooling that meaningfully reduces risk from tooling that only adds noise.
Experience operating or triaging a public or private bug bounty program on a platform such as HackerOne, Bugcrowd, or Intigriti.
Offensive security experience: penetration testing, exploit validation, or red-team operations, including familiarity with automated or agentic testing platforms.
Experience with infrastructure-as-code security (Terraform, CloudFormation) and shift-left security practices.
Experience securing containerized workloads, including image hardening, registry security, runtime protection, and familiarity with orchestration platforms such as Kubernetes or ECS.
Experience developing security automation or internal tooling beyond scripting, including work with security platform APIs and CI/CD integrations.
Exposure to SIEM/SOAR platforms and security telemetry pipelines.
Familiarity with zero trust network architecture (ZTNA) and micro-segmentation.
Relevant certifications: AWS Security Specialty, CCSP, CISSP, OSCP, CompTIA Security+, or equivalent.
Sedentary - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.
#LI-JM1
Benefits
Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.
Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.
CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/