1

Bug Bounty Program Jobs in California (NOW HIRING)

Run the vulnerability lifecycle end to end (triage, validation, prioritization, remediation) and help mature our bug bounty and disclosure programs. * Build AI-assisted security workflows, like ...

Establish and manage a bug bounty program and coordinate penetration testing across all product surfaces. Oversee triage, prioritization, and remediation tracking in partnership with engineering ...

Own and evolve the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows. Develop security standards, playbooks, and training programs that ...

Help run penetration testing, offensive security exercises, and support our bug bounty program. * Help respond to product security incidents. Anti-Abuse * Design and build technical systems to ...

Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...

Help run penetration testing, offensive security exercises, and support our bug bounty program. * Help respond to product security incidents. Anti-Abuse * Design and build technical systems to ...

Showing results 21-40

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in California? The most popular types of Bug Bounty Program jobs in California are:
What job categories do people searching Bug Bounty Program jobs in California look for? The top searched job categories for Bug Bounty Program jobs in California are:
What cities in California are hiring for Bug Bounty Program jobs? Cities in California with the most Bug Bounty Program job openings:
Infographic showing various Bug Bounty Program job openings in California as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Staff+ Security Engineer, Developer Tools

Verkada

San Mateo, CA • On-site

Full-time

Medical, Dental, Vision, PTO

Re-posted 18 days ago


Job description

Who We Are
Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and visitor management.
We've got serious momentum in the market: more than 30,000 customers (including 100+ of the Fortune 500), a $5.8B valuation, more than $1 billion in annualized bookings, and backing from CapitalG, Sequoia Capital, General Catalyst, Felicis Ventures, Next47 and more. Physical AI is one of the most consequential technology shifts of our time, and Verkada is at the center of it.
You can look at all kinds of communities to see our platform's impact in the world. It's the retailer that uses our agentic AI to deter theft before it happens. The warehouse that uses AI-powered alerts to make sure its team is protected on the floor with proper PPE. The school that's alerted to a threat in real-time and triggers a lockdown in seconds, not minutes. We're rapidly scaling this impact: today, more than 2 million Verkada devices are deployed across 170+ countries.
About the Role
We are looking for a security engineering leader to collaborate with the Developer Experience engineering team. As an embedded partner for the team, you will perform threat models, security design reviews and refine security tools that facilitate security throughout the SDLC. You will define the security roadmap, requirements and priorities to expand and enhance the tools, AI agents, and systems that empower our software engineers.
What You'll Do
  • Facilitate the security baked into our applications throughout the software development lifecycle
  • Evangelize software security best practices through training and information sharing
  • Partner closely with engineering and product teams to improve the security of Verkada's products and exceed customers' expectations
  • Explore innovative solutions to enable Verkada business instead of "Security says No"
  • Collaborate with other engineering leaders to define, communicate, and execute on goals, priorities and process
  • Set up security tooling and secure defaults to ensure software security best practices
  • Perform architecture analysis, threat modeling and technical design reviews of sensitive features and infrastructure
  • Create and operate a bug bounty program
  • Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties
  • Collaborate with the CISO and security team to grow the broader Verkada security program
  • Share your security experience with other teams internally and externally via security conferences and blogs
  • Help your peer engineers grow their own security reasoning and knowledge
What You Bring
  • Bachelor of Science in Computer Science degree or equivalent
  • Strong experience with AWS, GCP or other cloud service provider
  • 7+ years of experience as a security engineer, software engineer, site reliability engineer, or security consultant
  • Understanding of security weaknesses, exploits, attacks and mitigations
  • Experience and enthusiasm for learning about new security products, features, and strategies;
  • Coding ability. You will sometimes write production Python/Go code, security peer review code, build proofs of concept or implement automation scripts
  • Excellent collaborative skills
  • Outstanding written and verbal communication
  • Experience with most of the following:
    • Security Development Lifecycle
    • Threat Modeling
    • Architecture Analysis
    • Technical Design Review
    • Security Code Review
    • Open Policy Agent
    • SIEM
US Employee Benefits
Verkada is committed to fostering a workplace environment that prioritizes the holistic health and wellbeing of our employees and their families by offering comprehensive wellness perks, benefits, and resources. Our benefits and perks programs include, but are not limited to:
  • Healthcare programs that can be tailored to meet the personal health and financial well-being needs - Premiums are 100% covered for the employee under at least one plan and 80% for family premiums under all plans
  • Nationwide medical, vision and dental coverage
  • Health Saving Account (HSA) with annual employer contributions and Flexible Spending Account (FSA) with tax saving options
  • Expanded mental health support
  • Paid parental leave policy & fertility benefits
  • Time off to relax and recharge through our paid holidays, firmwide extended holidays, flexible PTO and personal sick time
  • Professional development stipend
  • Wellness/fitness benefits
  • Healthy lunches provided daily
  • Commuter benefits
Additional Information
  • We do sponsor and take over sponsorship of employment visas for this role. If we make you an offer, we will make every reasonable effort to get you a visa.

Annual Pay Range
At Verkada, we want to attract and retain the best employees, and compensate them in a way that appropriately and fairly values their individual contribution to the company. With that in mind, we carefully consider a number of factors to determine the appropriate starting pay for an employee, including their primary work location and an assessment of a candidate's skills and experience, as well as market demands and internal parity. A Verkada employee may be eligible for additional forms of compensation, depending on their role, including sales incentives, discretionary bonuses, and/or equity in the company in the form of restricted stock units (RSUs)
Below is the annual on-target earnings (OTE) range for full-time employees for this position, comprised of base compensation and commissions (if applicable).
Estimated Annual Pay Range
$200,000-$300,000 USD
Verkada Is An Equal Opportunity Employer
As an equal opportunity employer, Verkada is committed to providing employment opportunities to all individuals. All applicants for positions at Verkada will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
Your application will be handled in accordance with our Candidate Privacy Policy.