Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end. * Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports ...
Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end. * Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports ...
Staff+ Application Security Engineer - M&A
Seattle, WA · On-site
$67 - $89.50/hr
Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebasesTrack record of building security automation or tooling rather than relying ...
Staff+ Application Security Engineer - M&A
Seattle, WA · On-site
$67 - $89.50/hr
Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebasesTrack record of building security automation or tooling rather than relying ...
Security Engineer, Application Security
New York, NY · On-site
$130K - $400K/yr
Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes ... Experience managing a vulnerability pipeline - from discovery through prioritization to verified ...
Security Engineer, Application Security
New York, NY · On-site
$130K - $400K/yr
Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes ... Experience managing a vulnerability pipeline - from discovery through prioritization to verified ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews ... Own secure code review for high-risk changes - authentication, session management, cryptographic ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews ... Own secure code review for high-risk changes - authentication, session management, cryptographic ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews ... Own secure code review for high-risk changes - authentication, session management, cryptographic ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews ... Own secure code review for high-risk changes - authentication, session management, cryptographic ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Vulnerability Response Manager - Apple Information Security
Austin, TX · On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Vulnerability Response Manager - Apple Information Security
Austin, TX · On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Vulnerability Response Manager - Apple Information Security
Austin, TX · On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Vulnerability Response Manager - Apple Information Security
Austin, TX · On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Senior to Staff Application Security Engineer / Y Combinator Startup
Phoenix, AZ · On-site
$113K - $155K/yr
You'll run and build SAST/DAST pipelines, manage bug bounty program, and sit on new feature designs early to ensure security is built in, not added on. Ideal candidates have previous experience in ...
Senior to Staff Application Security Engineer / Y Combinator Startup
Phoenix, AZ · On-site
$113K - $155K/yr
You'll run and build SAST/DAST pipelines, manage bug bounty program, and sit on new feature designs early to ensure security is built in, not added on. Ideal candidates have previous experience in ...
Manager, Security Engineering
San Francisco, CA · On-site +1
Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...
Manager, Security Engineering
San Francisco, CA · On-site +1
Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...
Enterprise Account Executive
$116K - $160K/yr
Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions. * Familiarity with Salesforce and sales engagement tools. * A four-year degree from an accredited ...
Enterprise Account Executive
$116K - $160K/yr
Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions. * Familiarity with Salesforce and sales engagement tools. * A four-year degree from an accredited ...
$43.25 - $58/hr
... and bug bounty programs. * Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden. * Operationalize Continuous ...
$43.25 - $58/hr
... and bug bounty programs. * Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden. * Operationalize Continuous ...
Director Application Security
Austin, TX · On-site
$58.25 - $77.75/hr
... and bug bounty programs. * Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden. * Operationalize Continuous ...
Director Application Security
Austin, TX · On-site
$58.25 - $77.75/hr
... and bug bounty programs. * Partner with DevOps and engineering teams to automate security controls, streamline vulnerability management, and reduce developer burden. * Operationalize Continuous ...
... Security Manager (ISSM), Risk Management Framework (RMF), and cybersecurity risk management ... Bug Bounty Hunter VirtualHackingLabs Advanced+ Optional: GXPN, GWAPT, GRID, GPEN, CISSP, CCNA, CEH ...
Quick apply
... Security Manager (ISSM), Risk Management Framework (RMF), and cybersecurity risk management ... Bug Bounty Hunter VirtualHackingLabs Advanced+ Optional: GXPN, GWAPT, GRID, GPEN, CISSP, CCNA, CEH ...
$84K - $115K/yr
... key management, passwordless authentication, m2m authentication, sandboxing and compute/network ... Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ...
$84K - $115K/yr
... key management, passwordless authentication, m2m authentication, sandboxing and compute/network ... Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
Cybersecurity Engineer (Remote)
Lehi, UT · On-site
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Cybersecurity Engineer (Remote)
Lehi, UT · On-site
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands‑on work with bug bounty platforms. What we can offer you At Nscale ...
Bug Bounty Manager information
What is a bug bounty manager?
What does a bug bounty manager do?
What are the key skills and qualifications needed to thrive as a bug bounty manager?
What is the difference between Bug Bounty Manager vs Security Analyst?
| Aspect | Bug Bounty Manager | Security Analyst |
|---|---|---|
| Required Credentials | Certifications like OSCP, CEH, or CISSP; experience in bug bounty programs | Certifications such as CISSP, GIAC, or CEH; strong knowledge of security protocols |
| Work Environment | Focus on managing bug bounty programs, coordinating with researchers, and analyzing reports | Monitoring security systems, conducting vulnerability assessments, and incident response |
| Employer & Industry Usage | Tech companies, cybersecurity firms, organizations running bug bounty programs | Corporate security teams, government agencies, consulting firms |
The Bug Bounty Manager primarily oversees bug bounty initiatives, managing researcher collaborations and triaging reports. In contrast, a Security Analyst focuses on analyzing security threats, conducting assessments, and maintaining overall security posture. Both roles require security certifications and a strong understanding of vulnerabilities, but their daily tasks and focus areas differ significantly.
What cities are hiring for Bug Bounty Manager jobs?
Cities with the most Bug Bounty Manager job openings:
What are the most commonly searched types of Bug Bounty jobs?
The most popular types of Bug Bounty jobs are:
What states have the most Bug Bounty Manager jobs?
States with the most job openings for Bug Bounty Manager jobs include:
What are popular job titles related to Bug Bounty Manager jobs?
For Bug Bounty Manager jobs, the most frequently searched job titles are:

Security Software Engineer, Open Source Frameworks
San Francisco, CA • On-site
Other
Posted 26 days ago
Key responsibilities
Conduct deep security assessments of framework internals to identify systemic vulnerability patterns.
Drive framework-level fixes and design changes to eliminate classes of vulnerabilities across multiple projects.
Manage vulnerability disclosure processes, coordinate fixes, and oversee the open source bug bounty program.
Job description
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.
About the roleVercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company.
We’re looking for a security engineer who loves finding a whole class of vulnerability and eliminating it in one move, not someone who’s satisfied filing one bug at a time. You’ll run deep security assessments of framework internals (routing, middleware, caching, server actions, the build pipeline), find the systemic patterns that produce entire families of bugs, and drive the framework-level fixes and design changes that remove them permanently. You’ll also own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. This includes hands-on ownership of Vercel’s open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right maintainers.
What you will do- Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues.
- Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they’re reported.
- Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end.
- Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel’s open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers.
- Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in.
- Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before they land again.
- Own supply chain security for these projects: Harden how dependencies, releases, and published packages for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro are built, signed, and distributed. As more contributions and dependency updates are generated or assisted by AI agents, build the review and provenance practices that keep that increased volume safe.
- Work with the community, not around it: Engage directly with maintainers, contributors, and external researchers as peers. Bring pragmatic security recommendations to project discussions in a way that respects how these projects actually get built, and represent Vercel in coordinated disclosure norms and working groups when an issue spans multiple ecosystems.
- You've actually used or broken these frameworks: You've built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects), or you've found and reported security issues in them. This is a hard requirement, not a nice-to-have: we need someone who understands what these projects actually do and how they're actually used, not a generalist parachuting in.
- You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them, and you treat that with the seriousness it deserves. You're not here to slow the project down with process for its own sake.
- 4+ years in security engineering, ideally with real hands-on open source contribution experience. You've actually sent PRs to projects like these, not just filed issues against them.
- You're energized by root cause, not remediation count: Finding the one design flaw that kills fifty potential bugs is more satisfying to you than closing fifty tickets one at a time.
- You can read framework internals, not just application code: Strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood (routing, SSR/RSC, middleware, bundling/build systems).
- Pragmatic, not theoretical: You can weigh real-world risk against maintainer and community bandwidth, and land on security improvements that actually ship, rather than the theoretically ideal fix that never gets merged.
- Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories.
- Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike, in writing and in conversation.
- Comfortable operating in public: You're used to working transparently with external researchers, maintainers, and the community, not just inside a company's four walls.
- CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem.
- Maintained or heavily contributed to a widely used open source project.
- Experience with supply chain security tooling (Sigstore, SLSA/provenance, dependency and package scanning).
- Thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance.
- Run or triaged for a bug bounty / vulnerability disclosure program before, ideally for open source projects.
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.
About Cacheflow
Sourced by ZipRecruiter
Industry
Software development
Company size
11 - 50 Employees
Headquarters location
Los Altos, CA, US
Year founded
2021