1

Bug Bounty Program Jobs in California (NOW HIRING)

Software Engineer, Security

San Francisco, CA · On-site

$250K - $350K/yr

  • Medical

  • PTO

... bug bounty program, and coordinate remediation across engineering • Assist on compliance efforts like PCI and SOC 2 • Establish security patterns, tooling, and guardrails that enable the rest of ...

New

Senior Security Engineer

San Francisco, CA · On-site

$120 - $160/hr

  • Medical

  • Dental

  • PTO

Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing * Assess and integrate security tools to automate and scale ...

Create and operate a bug bounty program * Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties * Collaborate with the CISO and security team to grow ...

Software Engineer, Security

San Francisco, CA · On-site

$180K - $280K/yr

  • PTO

Run the vulnerability lifecycle end to end (triage, validation, prioritization, remediation) and help mature our bug bounty and disclosure programs. * Build AI-assisted security workflows, like ...

Staff Security Engineer

Palo Alto, CA · Remote

$240K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Own and evolve the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows. Develop security standards, playbooks, and training programs that ...

Establish and manage a bug bounty program and coordinate penetration testing across all product surfaces. Oversee triage, prioritization, and remediation tracking in partnership with engineering ...

Software Engineer II - Product Security

Los Angeles, CA · On-site

$165K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Triage and respond to findings from StubHub's enterprise Bug Bounty program. What You've Done: * Demonstrated expert-level understanding of offensive web application security testing and defense-in ...

Security Engineer

San Francisco, CA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Help run penetration testing, offensive security exercises, and support our bug bounty program. * Help respond to product security incidents. Anti-Abuse * Design and build technical systems to ...

Senior Security Application Engineer

San Francisco, CA · On-site

$200K - $235K/yr

  • Medical

  • Retirement

  • PTO

Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...

Showing results 21-40

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in California?

The most popular types of Bug Bounty Program jobs in California are:

What job categories do people searching Bug Bounty Program jobs in California look for?

The top searched job categories for Bug Bounty Program jobs in California are:

What cities in California are hiring for Bug Bounty Program jobs?

Cities in California with the most Bug Bounty Program job openings:

Infographic showing various Bug Bounty Program job openings in California as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 2% Temporary, and 2% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Software Engineer II - Product Security

StubHub

Los Angeles, CA • Hybrid

Full-time

Medical, Dental, Vision, Retirement

Posted 29 days ago


StubHub rating

7.2

Company rating: 7.2 out of 10

Based on 6 frontline employees who took The Breakroom Quiz

2nd of 4 rated ticket sellers


Job description

StubHub's Product Security Engineering Team is seeking a Software Engineer II to enhance our security posture within the end user and services product domain. The perfect candidate will possess experience in CI/CD pipeline security, product and application architecture reviews, contextualized vulnerability management processes, and automation. 

Location: Hybrid (3 days in office/2 days remote) - New York, NY or Century City, CA 

About the team: 

StubHub's Product Security Engineering Team plays a critical role in securing the platforms that power the world's largest ticket marketplace. This team works hands-on with cutting-edge tools and cloud-native technologies to embed security into every layer of the software development lifecycle-from architecture to automation. If you're passionate about offensive security, CI/CD hardening, and driving real impact across modern product teams, this is your opportunity to lead and innovate at global scale.

What You'll Do:

  • Conduct security assessments, code reviews, and penetration tests on web applications, APIs, and mobile apps to identify vulnerabilities and flaws. 
  • Collaborate with development teams to embed security into CI/CD pipelines, including the implementation of automated code scanning tools. 
  • Develop and maintain secure coding guidelines and conduct security awareness training for developers. 
  • Respond to security incidents, perform root cause analyses, and recommend effective remediations. 
  • Stay current on emerging security threats, vulnerabilities, and mitigation strategies; proactively share insights across teams. 
  • Help develop and enforce application security policies, standards, and procedures aligned with industry regulations and best practices. 
  • Conduct architectural reviews to ensure the security of new technologies and controls. 
  • Build and maintain robust product vulnerability management processes and procedures. 
  • Write and maintain production-grade APIs to automate security processes and streamline infrastructure and developer workflows. 
  • Triage and respond to findings from StubHub's enterprise Bug Bounty program. 

What You've Done:

  • Demonstrated expert-level understanding of offensive web application security testing and defense-in-depth remediation strategies. 
  • Expert-level skills in vulnerability assessments and code reviews. 
  • Extensive experience with automated security testing tools (e.g., Burp Suite, OWASP ZAP, Snyk). 
  • Strong communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences. 
  • Hands-on experience in applied cryptography and key management. 
  • Proven ability to implement SAST, DAST, and SBOM tooling within development workflows. 
  • Experience in performing structured threat modeling (e.g., STRIDE, PASTA). 
  • Intermediate proficiency in at least one scripting language (e.g., Python, Ruby). 
  • Familiarity with security frameworks such as PCI DSS, CIS, ISO 27001, and NIST CSF.

Preferred Skills and Qualifications: 

  • Industry-recognized security certifications (e.g., OSCP, CEH, CISSP, GWAPT). 
  • Intermediate-level experience with cloud security principles and technologies in AWS and Azure. 
  • Understanding of Kubernetes security fundamentals, including the use of admission controllers, network policies, role-based access control (RBAC), and ingress architecture design. 
  • Software development experience in Java & C#. 

What We Offer:

  • Accelerated Growth Environment: An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale.
  • Top Tier Compensation Package: Competitive base, equity, and upside that tracks with your impact.
  • Flexible Time Off: Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed.
  • Comprehensive Benefits Package: Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options.

What StubHub employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom