1

Bug Bounty Program Jobs in California (NOW HIRING)

Experience running a bug bounty program Additional Information Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based ...

Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...

Lead Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

... pen tests, bug bounty programs, or responsible disclosure programs end to end. • Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets. • ...

... Program and Bug Bounty programs What are we looking for? We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client ...

Senior Security Engineer, AI/ML

Foster City, CA · On-site

$130K - $179K/yr

Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications

Senior Security Engineer, AI/ML

Foster City, CA · On-site

$133K - $183K/yr

Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications

... bug bounty / responsible disclosure programs • Integrate security into Agile and CI/CD workflows • Secure software supply chain (SBOM, dependency scanning) • Implement artifact signing ...

Lead Security Engineer

San Francisco, CA · On-site

$210K - $240K/yr

... bug-bounty programs; AI controls, MCP security, agent security, and AI governance; and a background in corporate IT security. The role is right for you if: * You want to shape a security posture from ...

Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end. * Track record of partnering with engineering rather than blocking them. You ship paved roads, not ...

Showing results 41-60

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in California? The most popular types of Bug Bounty Program jobs in California are:
What job categories do people searching Bug Bounty Program jobs in California look for? The top searched job categories for Bug Bounty Program jobs in California are:
What cities in California are hiring for Bug Bounty Program jobs? Cities in California with the most Bug Bounty Program job openings:
Infographic showing various Bug Bounty Program job openings in California as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Security Engineer - Member of Technical Staff

Simile AI, Inc

San Francisco, CA • On-site

Full-time

Medical, Dental, Vision

Posted 13 days ago


Job description

About the Company
Simile is The Simulation Company. We simulate human behavior to keep people at the center of the decisions that shape the world. With AI, anyone can create a product, a campaign, a policy, or a script - the bottleneck has moved upstream. The hard question is no longer whether you can create something, but what to create, for whom, and how to bring it to life. Those are fundamentally human decisions, and they shouldn't be left to chance or handed off to an algorithm. We're building the infrastructure to understand human behavior at scale and to represent humans in an increasingly agentic world. Our mission is to simulate all eight billion people on earth.
We launched five months ago. Since then we've grown revenue 5x, built a new foundation model for human behavior that has run tens of millions of simulations for F100 enterprises, trained a first-of-its-kind confidence model that predicts the accuracy of every simulation, and released the first product that lets organizations verifiably predict the future. The world's leading companies use Simile to make business-critical decisions - from consumer leaders like CVS Health and Wealthfront to professional services organizations like Deloitte and Gallup - strategizing product launches, entering new markets, and forecasting earnings calls.
We've raised over $200M at a $2B post-money valuation led by Greenoaks, with Index Ventures, Hanabi, A*, Bain Capital Ventures, and CVS Health Ventures. We've grown from a small home in Palo Alto to a global team of 50+, and we're building a team of the best researchers, engineers, designers, and operators in the world. The future is too important to be left to chance.
About the Team
The Security team is the guardian of our simulation's integrity. We ensure that as we model human society, we do so with uncompromising privacy and world-class defenses. We operate at the intersection of application security, AI safety, and enterprise-grade privacy to protect our foundation models and our customers' most sensitive data.
We organize our work into three core pillars:
  • Application Security: Partnering with engineers to "shift left," conducting threat models and secure design reviews to catch vulnerabilities before they reach production.
  • Product and AI/ML Security: Defending our generative agents against emerging threats like prompt injection, data poisoning, and model extraction.
  • Infrastructure & Compliance: Hardening our multi-cloud footprint (AWS/GCP) and automating identity management (SAML/SCIM) to maintain SOC2 and HIPAA standards.

About the Role
We are looking for a Security Engineer who thrives on securing novel AI products. You will own the security roadmap, ensuring our platform is resilient, compliant, and stays ahead of an ever-evolving threat landscape.
Responsibilities
  • Customer Security & Trust: Partner with our largest enterprise customers to navigate the procurement process , leading technical discussions regarding security agreements, providing comprehensive posture overviews, and ensuring alignment on rigorous data handling requirements
  • Lead Secure Design: Conduct threat modeling and secure design reviews for new features, ensuring security is a core consideration from initial design through implementation.
  • Automate Defenses: Develop tooling and "paved paths" that allow our engineering and research teams to ship code safely without sacrificing velocity.
  • Own Vulnerability Management: Oversee our bug bounty program and internal vulnerability scanning, prioritizing fixes based on actual risk to our foundation models.
  • Secure AI/ML Pipelines: Build specific defenses against AI-novel risks, including protecting high-throughput inference systems and GPU-accelerated computing environments.
  • Champion GitOps Security: Manage security configurations via Terraform/Pulumi, ensuring "security-as-code" is the truth across all multi-region environments.

Requirements
Must Haves
  • Experience: 5+ years of experience in application or infrastructure security within a high-growth environment.
  • Security Polyglot: Deep expertise in securing AWS environments; experience with GCP or Azure is a major plus.
  • Offensive Mindset: Ability to think like an attacker to anticipate risks, paired with a collaborative spirit to help engineers remediate them.
  • Operational Mindset: Experience with modern observability and a "you build it, you run it" mentality toward security infrastructure.
  • Agentic Security Tooling: Experience integrating agentic AI workflows into the developer lifecycle to provide real-time security feedback, enabling engineers to be "secure-by-design" as code is written rather than after the fact.

Nice to Haves
  • AI/ML Security: Experience securing AI/ML workloads, specifically defending against prompt injection or protecting model weights.
  • Kubernetes Mastery: Strong K8s (EKS/GKE) experience, specifically around multi-tenant security and resource isolation.
  • Compliance Expertise: Proven track record of navigating SOC2, HIPAA, or similar regulatory frameworks in a cloud-native environment.

Compensation & Benefits
At Simile, we provide competitive compensation packages that include base salary, equity, and comprehensive benefits.
  • Salary Range: $200,000 - $400,000 USD
    • Note: Final offers are based on experience, specialized skills, interview performance, and relevant training.
  • Equity: Grants are available for eligible roles, subject to board approval.
  • Health & Wellness: Comprehensive medical, dental, and vision coverage.
  • Time Off: Flexible time off policies to support work-life balance.

Our Process
We prioritize thoughtful conversations and clear examples of past work. Our hiring journey is designed to help both sides align on fit, working style, and expectations.
Reapplication Policy: To ensure a fair and thorough evaluation for all applicants, Simile observes a 90-day waiting period before reconsidering candidates for the same role.
Commitment to Diversity & Inclusion
Equal Opportunity: Simile is an equal opportunity workplace. We welcome applicants of all backgrounds and identities, valuing an environment where everyone can contribute authentically.
Accommodations: If you require support or reasonable accommodations during the application process due to a disability, please let us know. We are happy to assist.