1

Bug Bounty Program Jobs in Ontario (NOW HIRING)

Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...

Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...

Application Security Developer

Toronto, ON · Hybrid

CA$137K - CA$157K/yr

Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program; * Identify and implement tools for automated application scanning, static ...

Lead the bug bounty program - Turn the global security community into an extension of our own team. * Influence roadmaps - Sit at the table with product leads, shaping priorities and ensuring ...

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are popular job titles related to Bug Bounty Program jobs in Ontario? For Bug Bounty Program jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Bug Bounty Program jobs in Ontario look for? The top searched job categories for Bug Bounty Program jobs in Ontario are:
Infographic showing various Bug Bounty Program job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Director, Offensive Security

Varicent

Toronto, ON • On-site

Full-time

Re-posted 3 days ago


Job description

At Varicent, we're not just transforming the Sales Performance Management (SPM) market—we're redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM, 2023 Ventana Research Revenue Performance Management (RPM) Value Index, Gartner Peer Insights, 2024 Gartner SPM Market Guide, and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here's why you'll thrive at Varicent:
  • Innovate with Purpose: Build impactful solutions for customers worldwide.
  • Join Excellence: Work in a diverse, collaborative, and innovative team.
  • Shape the Future: Lead in redefining revenue optimization.
  • Grow Together: Unlock your potential in a supportive environment.
Join us at Varicent—where your talent and ambition meet limitless opportunities for success!

About the Role

We're looking for a hands-on Director of Offensive Security to lead and evolve our offensive security program across applications, cloud environments, enterprise systems, and AI-enabled products.

This role combines technical expertise, strategic leadership, and cross-functional partnership to help identify, prioritize, and reduce security risk at scale. You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with Engineering, Product, Security, Compliance, and Legal teams.

What You'll Do

Lead the Offensive Security Program

  • Define and execute the offensive security strategy and roadmap.
  • Lead internal and external teams across penetration testing, red teaming, AI security testing, and vulnerability research.
  • Establish standards, reporting, and metrics that drive measurable risk reduction.

Drive Security Testing & Validation

  • Oversee web, API, mobile, cloud, and AI-enabled security testing.
  • Lead red team operations, adversary simulations, and purple team exercises.
  • Manage external penetration testing engagements and testing vendors.
  • Mature attack surface management and continuous security validation programs.

Secure AI-Enabled Products

  • Design and execute AI red teaming activities for LLM-enabled products and agentic workflows.
  • Partner with AI and engineering teams to integrate security throughout the AI development lifecycle.
  • Build scalable approaches for AI security testing, validation, and risk assessment.

Improve Vulnerability Management

  • Drive vulnerability triage, prioritization, remediation, and retesting.
  • Partner with engineering teams to implement risk-based remediation practices.
  • Mature bug bounty and vulnerability disclosure programs.

Influence Across the Business

  • Partner with Engineering, Product, Security Operations, Compliance, and Legal teams.
  • Communicate security risks, trends, and recommendations to senior leadership.
  • Help shape the future of AI-enabled offensive security across the organization.

What You'll Bring

  • 10+ years of Information Security experience, including 5+ years in Offensive Security and 3+ years in Development or Engineering.
  • Experience leading offensive security programs in SaaS and cloud environments.
  • Hands-on expertise in penetration testing, red teaming, vulnerability management, and security testing of AI-enabled products.
  • Strong understanding of application security, cloud security, attack surface management, and secure development practices.
  • Experience working with modern cloud environments, APIs, web applications, containers, and AI/LLM technologies.
  • Ability to translate technical findings into business risk and influence stakeholders at all levels.
  • Relevant certifications such as OSCP, OSWE, GXPN, GPEN, CISSP, CCSP, or cloud security certifications are considered an asset.

What Success Looks Like

First 90 Days

  • Assess the current offensive security landscape and identify key opportunities for improvement.
  • Build relationships across engineering, security, and business teams.
  • Establish priorities and define a roadmap for continuous security validation.

6+ Months

  • Scale AI-enabled offensive security capabilities.
  • Improve vulnerability management effectiveness and remediation outcomes.
  • Deliver measurable reductions in organizational security risk.

Long-term (7+ months): Mature, Measure & Reduce Risk

  • Scale autonomous vulnerability management across critical assets and environments.
  • Mature AI-enabled red team capabilities and continuous threat-informed security validation.
  • Drive measurable reductions in organizational risk through AI-enabled offensive security capabilities.

For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 (CAD). In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.

This posting is for a new vacancy.

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision-making.

Overview of Benefits:

  • Health & Wellness— Comprehensive medical, dental, and vision coverage tailored to your local needs
  • Time Off— PTO and public holidays to rest, recharge, and do what matters most
  • Volunteer Days— Dedicated time to give back and support the communities that matter to you
  • Ignite Days— Dedicated learning days to support continuous growth, skill development, and professional learning
  • Financial— Compensation that reflects your market and your value
  • Retirement— Retirement plans designed to help you build long-term financial security
  • Tuition Assistance— Invest in your growth with support for continuing education and professional development
  • Flexibility— Work where you thrive, with remote and hybrid options available across most regions
Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com
Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact