1

Bug Bounty Manager Jobs (NOW HIRING)

Job Summary We are looking for an innovative Staff Product Manager, AI & Data to define the vision ... tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized ...

You understand how different test types (vulnerability scanning, penetration testing, bug bounty ... Experience building or product-managing systems that use ML for entity resolution, deduplication ...

$105K/yr

... management programs. You will own the tooling that continuously tests our environment -- bug bounty, agentic red team, CSPM, and vulnerability scanners -- turn the output of those platforms into a ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified ... Bug Bounty Triage: Perform the technical triage and validation of Cloudflare's external Bug Bounty ...

Senior Product Security Engineer

Austin, TX ยท On-site

$113K - $155K/yr

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug ... Proven track record of managing, routing, and driving the remediation of vulnerabilities across ...

Security & Compliance Lead

San Francisco, CA ยท On-site

$120K - $200K/yr

Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation ...

... Bug Bounty & Vulnerability Management Be the primary owner of our ImmuneFi program - triaging, reproducing, and responding to incoming submissions daily Prioritize and track vulnerabilities through ...

Showing results 21-40

Bug Bounty Manager information

What is a bug bounty manager?

Bug Bounty Managers are professionals responsible for overseeing bug bounty programs, which incentivize security researchers to find and report vulnerabilities in a company's software or systems. They coordinate the design, implementation, and management of these programs, ensuring that reported issues are validated, prioritized, and addressed efficiently. Bug Bounty Managers also communicate with security researchers, internal security teams, and stakeholders to improve the organization's security posture. Their role is crucial in fostering a collaborative relationship between the organization and the security community.

What does a bug bounty manager do?

A Bug Bounty Manager typically spends the week overseeing vulnerability reports, coordinating with security researchers, and prioritizing remediation efforts with engineering teams. They review incoming submissions, validate findings, and communicate with both internal stakeholders and external participants to ensure clear understanding and timely resolution of issues. Collaboration is key in this role, as managers often work closely with developers, legal, and compliance teams to align on security priorities and program updates. Additionally, they may analyze program metrics and provide feedback to improve the bounty process.

What are the key skills and qualifications needed to thrive as a bug bounty manager?

To thrive as a Bug Bounty Manager, you need expertise in cybersecurity, vulnerability management, and a solid understanding of software development, typically supported by a degree in computer science or related field. Familiarity with bug bounty platforms (such as HackerOne or Bugcrowd), vulnerability tracking tools, and relevant certifications like CISSP or CEH is important. Strong communication, analytical thinking, and stakeholder management skills help you coordinate between security researchers and internal teams. These skills ensure effective vulnerability reporting, timely remediation, and the overall security posture of the organization.

What is the difference between Bug Bounty Manager vs Security Analyst?

AspectBug Bounty ManagerSecurity Analyst
Required CredentialsCertifications like OSCP, CEH, or CISSP; experience in bug bounty programsCertifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols
Work EnvironmentFocus on managing bug bounty programs, coordinating with researchers, and analyzing reportsMonitoring security systems, conducting vulnerability assessments, and incident response
Employer & Industry UsageTech companies, cybersecurity firms, organizations running bug bounty programsCorporate security teams, government agencies, consulting firms

The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.

More about Bug Bounty Manager jobs

What cities are hiring for Bug Bounty Manager jobs?

Cities with the most Bug Bounty Manager job openings:

What are the most commonly searched types of Bug Bounty jobs?

The most popular types of Bug Bounty jobs are:

What states have the most Bug Bounty Manager jobs?

States with the most job openings for Bug Bounty Manager jobs include:

What are popular job titles related to Bug Bounty Manager jobs?

For Bug Bounty Manager jobs, the most frequently searched job titles are:

Infographic showing various Bug Bounty Manager job openings in the United States as of September 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 75% In-person, and 25% Remote job distribution.

Senior Security Engineer

Augusta, GA โ€ข On-site

$107K - $147K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 21 days ago


Key responsibilities

  • Review product features, system designs, APIs, authentication mechanisms, and third-party integrations to identify and mitigate security risks.

  • Conduct secure code reviews, threat modeling activities, architecture risk assessments, and security testing for applications and product releases.

  • Manage and optimize SAST, DAST, and CI/CD security tooling and processes.


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Senior Security Engineer

Full Time Augusta, GA, US

Senior Security Engineer- Product Security

Augusta, Ga

Work Location & Schedule

This is a hybrid position based in our Augusta, GA office. Team members are expected to work on-site two days per week in our Augusta office andremotely three days per week. This schedule supports collaboration while offering flexibility and work-life balance.
For the right candidate, this position may also be considered as a fully remote opportunity for individuals residing in Georgia, South Carolina, North Carolina, Florida, or Tennessee only.

Who we are:

At TaxSlayer, we're more than just a tax software development company; weโ€™re empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease. As a leading innovator in tax prep software, TaxSlayer, LLC, has been revolutionizing the way people file their taxes since 1965. Our user-friendly platform offers an intuitive interface that guides customers through the tax-filing process step by step, ensuring accuracy and maximum refunds.

TaxSlayer is headquartered in Augusta, GA with a satellite office in Charlotte, NC. TaxSlayer proudly employs nearly 200 individuals year-round, plus 300 additional in-season support agents. Our employees are among the brightest, most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season.

About the Role

The Senior Security Engineer โ€“ Product Security serves as the primary security partner to software development teams, helping ensure security is embedded throughout the software development lifecycle. This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk management initiatives. Working closely with engineering, product, and Information Security teams, this position helps protect sensitive taxpayer and financial data while fostering secure development practices across the organization.

Core Responsibilities
  • Serve as the primary security point of contact for assigned Development teams, participating in sprint planning, architecture discussions, and design reviews.
  • Review product features, system designs, APIs, authentication mechanisms, and third-party integrations to identify and mitigate security risks.
  • Partner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practices.
  • Conduct secure code reviews, threat modeling activities, architecture risk assessments, and security testing for applications and product releases.
  • Perform hands-on penetration testing and coordinate third-party testing efforts when appropriate.
  • Manage and optimize SAST, DAST, and CI/CD security tooling and processes.
  • Track identified vulnerabilities through remediation and collaborate with engineering teams to address findings.
  • Own day-to-day administration of the company's bug bounty program, including researcher engagement, submission triage, validation, and remediation coordination.
  • Monitor and report bug bounty program performance metrics and recommend process improvements.
  • Support governance, risk, and compliance initiatives, including audits and assessments related to PCI DSS, SOC 2, IRS security requirements, and other applicable regulations.
  • Contribute to enterprise risk management activities and maintain product-level security risk documentation.
  • Assist with security incident response activities, including investigation, root cause analysis, and remediation tracking.
  • Mentor engineering teams on secure coding practices, threat modeling, and product security best practices.
  • Other duties as assigned.
How your Success is measured
  • Reduction in application and product security vulnerabilities identified in production environments.
  • Timely completion of security reviews, threat models, and vulnerability remediation activities.
  • Effective integration of security controls within the software development lifecycle.
  • Successful management and continuous improvement of the bug bounty program, including response and remediation timelines.
  • Positive audit and compliance assessment outcomes related to product security controls.
  • Increased adoption of secure coding practices and security standards across development teams.
  • Clear communication of technical risks and effective collaboration with engineering and business stakeholders.
Education & Experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent combination of education and experience.
  • Minimum of 5 years of experience in application security, product security, security engineering, or a related field.
  • Experience partnering closely with software development teams to integrate security into the development lifecycle.
  • Experience identifying and validating vulnerabilities in web applications, APIs, and cloud-based environments.
  • Strong knowledge of secure software development lifecycle (SDLC) practices.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Knowledge of common vulnerability frameworks including OWASP Top 10 and CWE/SANS Top 25.
  • Experience with SAST, DAST, penetration testing, code review, and CI/CD security tools.
  • Strong understanding of web application, API, and cloud security principles.
  • Ability to assess and communicate technical security risks to technical and non-technical audiences.
  • Strong problem-solving, collaboration, and relationship-building skills.
  • Ability to balance security requirements with business objectives and product delivery schedules.
  • Preferred certifications include OSCP, OSWE, GWAPT, CSSLP, or comparable credentials.
  • Experience with bug bounty or vulnerability disclosure programs is strongly preferred.
  • Familiarity with regulatory frameworks including PCI DSS, SOC 2, FTC Safeguards Rule, IRS security requirements, CCPA, and related standards is preferred.
Physical & Work Environment Requirements
  • This is a hybrid or remote role.
  • Work is performed in a standard office environment with minimal physical demands.
  • Must be able to work at a computer for extended periods.
  • Occasional travel may be required for meetings, training, or business needs.
What We Offer

At TaxSlayer, we know that our greatest strength lies in the talented individuals who drive our innovation and success. Thatโ€™s why weโ€™re proud to offer a competitive, comprehensive, and flexible benefits package designed to support your well-being, growth, and work-life balance.

Flexible Work Options
Enjoy remote and hybrid work opportunities, depending on the role and team needs.

Generous Time Off
Full Time employees receive a robust PTO bank, plus paid holidays to recharge and refresh.

Health & Wellness Coverage

  • Medical, Dental, and Vision insurance through Aetna and SunLife
  • Coverage options include: Employee Only, Employee + Spouse/Domestic Partner, Employee + Children, or Family
  • Access to a Wellness Program and on-site fitness facility
  • 401(k) with a 150% match on up to 3% of your contribution
  • Performance-based bonuses and regular salary reviews
  • Company-paid life insurance, short-term and long-term disability
  • Optional critical illness and accident insurance
  • Education assistance to support your professional development
  • Company-paid parking, company store, and unlimited free coffee
Please note:

As a federal contractor, we are responsible to ensure our employees meet any obligations set forth by the U.S. government. We will inform you of any applicable requirements as they arise.

Legal Disclaimers

TaxSlayer is an equal opportunity employer and complies with all applicable laws regarding discrimination. Employment is based on qualifications, merit, and business need. This job description is not intended to be all-inclusive and may be subject to change to meet business needs

#J-18808-Ljbffr