Oversee our bug bounty program and internal vulnerability scanning, prioritizing fixes based on actual risk to our foundation models. * Secure AI/ML Pipelines: Build specific defenses against AI ...
Oversee our bug bounty program and internal vulnerability scanning, prioritizing fixes based on actual risk to our foundation models. * Secure AI/ML Pipelines: Build specific defenses against AI ...
Senior Security Engineer
San Francisco, CA · On-site
$168K - $280K/yr
Experience running a bug bounty program Additional Information Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based ...
Senior Security Engineer
San Francisco, CA · On-site
$168K - $280K/yr
Experience running a bug bounty program Additional Information Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based ...
Senior Application Security Engineer - Moveworks
Mountain View, CA · On-site
$69.25 - $92.50/hr
You will also triage and address findings from SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) scans, as well as reports from our Bug Bounty program. This ...
Senior Application Security Engineer - Moveworks
Mountain View, CA · On-site
$69.25 - $92.50/hr
You will also triage and address findings from SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) scans, as well as reports from our Bug Bounty program. This ...
Senior Application Security Engineer - Moveworks
Mountain View, CA · On-site
$69.25 - $92.50/hr
You will also triage and address findings from SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) scans, as well as reports from our Bug Bounty program. This ...
Senior Application Security Engineer - Moveworks
Mountain View, CA · On-site
$69.25 - $92.50/hr
You will also triage and address findings from SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) scans, as well as reports from our Bug Bounty program. This ...
Senior Security Application Engineer
Palo Alto, CA · On-site
$200K - $235K/yr
Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...
Senior Security Application Engineer
Palo Alto, CA · On-site
$200K - $235K/yr
Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...
Lead Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... pen tests, bug bounty programs, or responsible disclosure programs end to end. • Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets. • ...
Lead Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... pen tests, bug bounty programs, or responsible disclosure programs end to end. • Track record of partnering with engineering rather than blocking them. You ship paved roads, not tickets. • ...
Senior Security Application Engineer
San Francisco, CA · On-site
$200K - $235K/yr
Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...
Senior Security Application Engineer
San Francisco, CA · On-site
$200K - $235K/yr
Oversee operational security initiatives including corporate bug bounty programs, incident response workflows, and regular penetration testing engagements. * Secure next-generation AI-integrated ...
Security & Compliance Operations Manager
San Francisco, CA · On-site
$120K - $180K/yr
... bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences ... programs) * Coordinate, don't silo - route technical work to Engineering DRIs with clear asks, and ...
Security & Compliance Operations Manager
San Francisco, CA · On-site
$120K - $180K/yr
... bug bounty coordination (triage, researcher comms, payouts), trainings and access-review cadences ... programs) * Coordinate, don't silo - route technical work to Engineering DRIs with clear asks, and ...
Director, Ecosystem Product Security
San Francisco, CA · On-site
$225K - $320K/yr
Lead secure development efforts across architecture, threat modeling, vulnerability management, bug bounty programs, and product incident response * Build and lead a high-performing security team ...
Director, Ecosystem Product Security
San Francisco, CA · On-site
$225K - $320K/yr
Lead secure development efforts across architecture, threat modeling, vulnerability management, bug bounty programs, and product incident response * Build and lead a high-performing security team ...
AVP, Penetration Tester
San Diego, CA · On-site
... Program and Bug Bounty programs What are we looking for? We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client ...
AVP, Penetration Tester
San Diego, CA · On-site
... Program and Bug Bounty programs What are we looking for? We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client ...
Senior Security Engineer, AI/ML
Foster City, CA · On-site
$130K - $179K/yr
Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications
Senior Security Engineer, AI/ML
Foster City, CA · On-site
$130K - $179K/yr
Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications
Senior Security Engineer, AI/ML
Foster City, CA · On-site
$133K - $183K/yr
Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications
Senior Security Engineer, AI/ML
Foster City, CA · On-site
$133K - $183K/yr
Strong analytical mindset, excellent technical writing skills, and familiarity with responsible disclosure practices, bug bounty programs, or security research ethics. Preferred Qualifications
... bug bounty / responsible disclosure programs • Integrate security into Agile and CI/CD workflows • Secure software supply chain (SBOM, dependency scanning) • Implement artifact signing ...
... bug bounty / responsible disclosure programs • Integrate security into Agile and CI/CD workflows • Secure software supply chain (SBOM, dependency scanning) • Implement artifact signing ...
Lead Security Engineer
San Francisco, CA · On-site
$210K - $240K/yr
... bug-bounty programs; AI controls, MCP security, agent security, and AI governance; and a background in corporate IT security. The role is right for you if: * You want to shape a security posture from ...
Lead Security Engineer
San Francisco, CA · On-site
$210K - $240K/yr
... bug-bounty programs; AI controls, MCP security, agent security, and AI governance; and a background in corporate IT security. The role is right for you if: * You want to shape a security posture from ...
Lead Application Security Engineer
San Francisco, CA · On-site
$220K - $300K/yr
Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end. * Track record of partnering with engineering rather than blocking them. You ship paved roads, not ...
Lead Application Security Engineer
San Francisco, CA · On-site
$220K - $300K/yr
Experience managing pen tests, bug bounty programs, or responsible disclosure programs end to end. * Track record of partnering with engineering rather than blocking them. You ship paved roads, not ...
Director of Software Security
San Jose, CA · On-site
$164K - $305K/yr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows Supply Chain & Software Integrity * Secure software supply chain (SBOM, dependency scanning)
Director of Software Security
San Jose, CA · On-site
$164K - $305K/yr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows Supply Chain & Software Integrity * Secure software supply chain (SBOM, dependency scanning)
Director of Software Security
San Jose, CA · On-site
$164K - $305K/yr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows Supply Chain & Software Integrity * Secure software supply chain (SBOM, dependency scanning)
Director of Software Security
San Jose, CA · On-site
$164K - $305K/yr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows Supply Chain & Software Integrity * Secure software supply chain (SBOM, dependency scanning)
Director of Software Security
San Jose, CA · On-site
$164.50 - $305.50/hr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows * Secure software supply chain (SBOM, dependency scanning) * Implement artifact signing ...
Director of Software Security
San Jose, CA · On-site
$164.50 - $305.50/hr
Establish bug bounty / responsible disclosure programs * Integrate security into Agile and CI/CD workflows * Secure software supply chain (SBOM, dependency scanning) * Implement artifact signing ...
Senior Staff Security Engineer, Ripple Treasury
$134K - $185K/yr
... program. * Own vulnerability discovery via security assessments, penetration testing and bug bounty, driving findings through triage, prioritization, remediation, and validation with a bias toward ...
Senior Staff Security Engineer, Ripple Treasury
$134K - $185K/yr
... program. * Own vulnerability discovery via security assessments, penetration testing and bug bounty, driving findings through triage, prioritization, remediation, and validation with a bias toward ...
Security Engineer, Application
San Francisco, CA · On-site
$200K - $325K/yr
... bug bounty; triage and severity assessment; SLAs and remediation tracking; and coordinated ... Build a security program capable of withstanding sophisticated adversaries, including by tackling ...
Security Engineer, Application
San Francisco, CA · On-site
$200K - $325K/yr
... bug bounty; triage and severity assessment; SLAs and remediation tracking; and coordinated ... Build a security program capable of withstanding sophisticated adversaries, including by tackling ...
Bug Bounty Program information
What are some common challenges faced by professionals managing a bug bounty program?
What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?
What is a bug bounty program?
What is the difference between Bug Bounty Program vs Penetration Tester?
| Aspect | Bug Bounty Program | Penetration Tester |
|---|---|---|
| Credentials | Knowledge of security vulnerabilities, bug reporting skills | Certifications like OSCP, CEH, CISSP often preferred |
| Work Environment | Remote, project-based, crowdsourced | Consulting firms, in-house teams, on-site or remote |
| Industry Usage | Tech companies, startups, open security initiatives | Security firms, corporate security teams, government agencies |
| Search/Comparison Intent | Understanding crowdsourced bug finding vs professional testing | Comparing freelance or company-based security assessments |
The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

Full-time
Medical, Dental, Vision
Posted 13 days ago
Job description
Simile is The Simulation Company. We simulate human behavior to keep people at the center of the decisions that shape the world. With AI, anyone can create a product, a campaign, a policy, or a script - the bottleneck has moved upstream. The hard question is no longer whether you can create something, but what to create, for whom, and how to bring it to life. Those are fundamentally human decisions, and they shouldn't be left to chance or handed off to an algorithm. We're building the infrastructure to understand human behavior at scale and to represent humans in an increasingly agentic world. Our mission is to simulate all eight billion people on earth.
We launched five months ago. Since then we've grown revenue 5x, built a new foundation model for human behavior that has run tens of millions of simulations for F100 enterprises, trained a first-of-its-kind confidence model that predicts the accuracy of every simulation, and released the first product that lets organizations verifiably predict the future. The world's leading companies use Simile to make business-critical decisions - from consumer leaders like CVS Health and Wealthfront to professional services organizations like Deloitte and Gallup - strategizing product launches, entering new markets, and forecasting earnings calls.
We've raised over $200M at a $2B post-money valuation led by Greenoaks, with Index Ventures, Hanabi, A*, Bain Capital Ventures, and CVS Health Ventures. We've grown from a small home in Palo Alto to a global team of 50+, and we're building a team of the best researchers, engineers, designers, and operators in the world. The future is too important to be left to chance.
About the Team
The Security team is the guardian of our simulation's integrity. We ensure that as we model human society, we do so with uncompromising privacy and world-class defenses. We operate at the intersection of application security, AI safety, and enterprise-grade privacy to protect our foundation models and our customers' most sensitive data.
We organize our work into three core pillars:
- Application Security: Partnering with engineers to "shift left," conducting threat models and secure design reviews to catch vulnerabilities before they reach production.
- Product and AI/ML Security: Defending our generative agents against emerging threats like prompt injection, data poisoning, and model extraction.
- Infrastructure & Compliance: Hardening our multi-cloud footprint (AWS/GCP) and automating identity management (SAML/SCIM) to maintain SOC2 and HIPAA standards.
About the Role
We are looking for a Security Engineer who thrives on securing novel AI products. You will own the security roadmap, ensuring our platform is resilient, compliant, and stays ahead of an ever-evolving threat landscape.
Responsibilities
- Customer Security & Trust: Partner with our largest enterprise customers to navigate the procurement process , leading technical discussions regarding security agreements, providing comprehensive posture overviews, and ensuring alignment on rigorous data handling requirements
- Lead Secure Design: Conduct threat modeling and secure design reviews for new features, ensuring security is a core consideration from initial design through implementation.
- Automate Defenses: Develop tooling and "paved paths" that allow our engineering and research teams to ship code safely without sacrificing velocity.
- Own Vulnerability Management: Oversee our bug bounty program and internal vulnerability scanning, prioritizing fixes based on actual risk to our foundation models.
- Secure AI/ML Pipelines: Build specific defenses against AI-novel risks, including protecting high-throughput inference systems and GPU-accelerated computing environments.
- Champion GitOps Security: Manage security configurations via Terraform/Pulumi, ensuring "security-as-code" is the truth across all multi-region environments.
Requirements
Must Haves
- Experience: 5+ years of experience in application or infrastructure security within a high-growth environment.
- Security Polyglot: Deep expertise in securing AWS environments; experience with GCP or Azure is a major plus.
- Offensive Mindset: Ability to think like an attacker to anticipate risks, paired with a collaborative spirit to help engineers remediate them.
- Operational Mindset: Experience with modern observability and a "you build it, you run it" mentality toward security infrastructure.
- Agentic Security Tooling: Experience integrating agentic AI workflows into the developer lifecycle to provide real-time security feedback, enabling engineers to be "secure-by-design" as code is written rather than after the fact.
Nice to Haves
- AI/ML Security: Experience securing AI/ML workloads, specifically defending against prompt injection or protecting model weights.
- Kubernetes Mastery: Strong K8s (EKS/GKE) experience, specifically around multi-tenant security and resource isolation.
- Compliance Expertise: Proven track record of navigating SOC2, HIPAA, or similar regulatory frameworks in a cloud-native environment.
Compensation & Benefits
At Simile, we provide competitive compensation packages that include base salary, equity, and comprehensive benefits.
- Salary Range: $200,000 - $400,000 USD
- Note: Final offers are based on experience, specialized skills, interview performance, and relevant training.
- Equity: Grants are available for eligible roles, subject to board approval.
- Health & Wellness: Comprehensive medical, dental, and vision coverage.
- Time Off: Flexible time off policies to support work-life balance.
Our Process
We prioritize thoughtful conversations and clear examples of past work. Our hiring journey is designed to help both sides align on fit, working style, and expectations.
Reapplication Policy: To ensure a fair and thorough evaluation for all applicants, Simile observes a 90-day waiting period before reconsidering candidates for the same role.
Commitment to Diversity & Inclusion
Equal Opportunity: Simile is an equal opportunity workplace. We welcome applicants of all backgrounds and identities, valuing an environment where everyone can contribute authentically.
Accommodations: If you require support or reasonable accommodations during the application process due to a disability, please let us know. We are happy to assist.