Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...
Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...
Director, Offensive Security
Toronto, ON · On-site
CA$138K - CA$181K/yr
Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...
Director, Offensive Security
Toronto, ON · On-site
CA$138K - CA$181K/yr
Mature bug bounty and vulnerability disclosure programs. Influence Across the Business * Partner with Engineering, Product, Security Operations, Compliance, and Legal teams. * Communicate security ...
Proven ability to hack software, discover flaws, and suggest improvements, demonstrated through activities such as CTFs, bug bounty programs, and open-source project contribution At Trend Micro, we ...
Proven ability to hack software, discover flaws, and suggest improvements, demonstrated through activities such as CTFs, bug bounty programs, and open-source project contribution At Trend Micro, we ...
Manage our bug bounty program, and track the progress of the bugs raised to the engineering teams. * Be part of the incident response team for any security incidents. * Innovate by proposing and ...
Manage our bug bounty program, and track the progress of the bugs raised to the engineering teams. * Be part of the incident response team for any security incidents. * Innovate by proposing and ...
Sr. Security Researcher - Toronto, ON
Toronto, ON · On-site +1
Abilitiesdemonstratedthrough activities such as CTFs, bug bounty programs, and open-source projectcontribution. * Proventrack recordof quality publications in the areas of security and machine ...
Sr. Security Researcher - Toronto, ON
Toronto, ON · On-site +1
Abilitiesdemonstratedthrough activities such as CTFs, bug bounty programs, and open-source projectcontribution. * Proventrack recordof quality publications in the areas of security and machine ...
Application Security Developer
Toronto, ON · Hybrid
CA$119K - CA$161K/yr
Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program; * Identify and implement tools for automated application scanning, static ...
Application Security Developer
Toronto, ON · Hybrid
CA$119K - CA$161K/yr
Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program; * Identify and implement tools for automated application scanning, static ...
Lead the bug bounty program - Turn the global security community into an extension of our own team. * Influence roadmaps - Sit at the table with product leads, shaping priorities and ensuring ...
Lead the bug bounty program - Turn the global security community into an extension of our own team. * Influence roadmaps - Sit at the table with product leads, shaping priorities and ensuring ...
Bug Bounty Program information
What is a bug bounty program?
What are some common challenges faced by professionals managing a bug bounty program?
What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?
What is the difference between Bug Bounty Program vs Penetration Tester?
| Aspect | Bug Bounty Program | Penetration Tester |
|---|---|---|
| Credentials | Knowledge of security vulnerabilities, bug reporting skills | Certifications like OSCP, CEH, CISSP often preferred |
| Work Environment | Remote, project-based, crowdsourced | Consulting firms, in-house teams, on-site or remote |
| Industry Usage | Tech companies, startups, open security initiatives | Security firms, corporate security teams, government agencies |
| Search/Comparison Intent | Understanding crowdsourced bug finding vs professional testing | Comparing freelance or company-based security assessments |
The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.
What are popular job titles related to Bug Bounty Program jobs in Ontario?
For Bug Bounty Program jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Bug Bounty Program jobs in Ontario look for?
The top searched job categories for Bug Bounty Program jobs in Ontario are:

Full-time
Re-posted 23 days ago
Job description
- Innovate with Purpose: Build impactful solutions for customers worldwide.
- Join Excellence: Work in a diverse, collaborative, and innovative team.
- Shape the Future: Lead in redefining revenue optimization.
- Grow Together: Unlock your potential in a supportive environment.
About the Role
We're looking for a hands-on Director of Offensive Security to lead and evolve our offensive security program across applications, cloud environments, enterprise systems, and AI-enabled products.
This role combines technical expertise, strategic leadership, and cross-functional partnership to help identify, prioritize, and reduce security risk at scale. You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with Engineering, Product, Security, Compliance, and Legal teams.
What You'll Do
Lead the Offensive Security Program
- Define and execute the offensive security strategy and roadmap.
- Lead internal and external teams across penetration testing, red teaming, AI security testing, and vulnerability research.
- Establish standards, reporting, and metrics that drive measurable risk reduction.
Drive Security Testing & Validation
- Oversee web, API, mobile, cloud, and AI-enabled security testing.
- Lead red team operations, adversary simulations, and purple team exercises.
- Manage external penetration testing engagements and testing vendors.
- Mature attack surface management and continuous security validation programs.
Secure AI-Enabled Products
- Design and execute AI red teaming activities for LLM-enabled products and agentic workflows.
- Partner with AI and engineering teams to integrate security throughout the AI development lifecycle.
- Build scalable approaches for AI security testing, validation, and risk assessment.
Improve Vulnerability Management
- Drive vulnerability triage, prioritization, remediation, and retesting.
- Partner with engineering teams to implement risk-based remediation practices.
- Mature bug bounty and vulnerability disclosure programs.
Influence Across the Business
- Partner with Engineering, Product, Security Operations, Compliance, and Legal teams.
- Communicate security risks, trends, and recommendations to senior leadership.
- Help shape the future of AI-enabled offensive security across the organization.
What You'll Bring
- 10+ years of Information Security experience, including 5+ years in Offensive Security and 3+ years in Development or Engineering.
- Experience leading offensive security programs in SaaS and cloud environments.
- Hands-on expertise in penetration testing, red teaming, vulnerability management, and security testing of AI-enabled products.
- Strong understanding of application security, cloud security, attack surface management, and secure development practices.
- Experience working with modern cloud environments, APIs, web applications, containers, and AI/LLM technologies.
- Ability to translate technical findings into business risk and influence stakeholders at all levels.
- Relevant certifications such as OSCP, OSWE, GXPN, GPEN, CISSP, CCSP, or cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
- Assess the current offensive security landscape and identify key opportunities for improvement.
- Build relationships across engineering, security, and business teams.
- Establish priorities and define a roadmap for continuous security validation.
6+ Months
- Scale AI-enabled offensive security capabilities.
- Improve vulnerability management effectiveness and remediation outcomes.
- Deliver measurable reductions in organizational security risk.
Long-term (7+ months): Mature, Measure & Reduce Risk
- Scale autonomous vulnerability management across critical assets and environments.