1

Bug Bounty Program Jobs in Oregon (NOW HIRING)

Principal Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

Drive our security assessment, penetration testing and bug bounty programs * Participate in security incident response In order to be successful in this role you must have: * Demonstrated technical ...

Manager, Application Security

OR · Remote

$58.75 - $78.50/hr

Oversee our Bug Bounty program, external penetration testing partners, and security tooling vendors (SAST, DAST, SCA). * Evangelize Security: Build a "Security Champions" program to scale security ...

Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

Take part in our security assessment, penetration testing and bug bounty programs * Participate in security incident response The duties and responsibilities described above may provide only a ...

OR

$58.75 - $78.50/hr

Participate in and help scale internal security assessments, penetration testing, and bug bounty programs. * Tooling Ownership: Evaluate, prototype, implement, and operate security tools including ...

OR · On-site

$114.40K - $156.80K/yr

Strong experience with code review, security reviews, security architecture, pentesting, and bug bounty programs * Experience working in full-stack projects * Experience with discovering and fixing ...

Senior Offensive Security Engineer

OR · On-site +1

$114.40K - $156.80K/yr

... program and encourage participation. * Receive and triage vulnerability reports submitted by external researchers through various channels, such as email, web form, or bug bounty platform.

OR

$114.40K - $156.80K/yr

... coordination, bug bounty intake, and prioritization of findings into durable engineering ... Experience leading security engineering programs in at least two of the following domains ...

Bug Bounty Program information

What are the key skills and qualifications needed to thrive as a Bug Bounty Program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What are some common challenges faced by professionals managing a Bug Bounty Program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What is a Bug Bounty Program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Oregon? The most popular types of Bug Bounty Program jobs in Oregon are:
What are popular job titles related to Bug Bounty Program jobs in Oregon? For Bug Bounty Program jobs in Oregon, the most frequently searched job titles are:
Principal Application Security Engineer

Principal Application Security Engineer

iHerb

Remote

$58.75 - $78.50/hr

Other

Posted 15 days ago


iHerb rating

7.4

Company rating: 7.4 out of 10

Based on 12 frontline employees who took The Breakroom Quiz


Job description

Summary:

Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role can be fully remote and must reside in US.

In this role, you will help us drive our Product Security strategy working with development teams globally to define new security capabilities, grow the team by hiring the best talent, and partner with senior leaders across the organization to deliver company-wide security initiatives. 

Responsibilities Include::

  • Lead cross-functional projects and establish cutting-edge security development lifecycle practices

  • Directed security design reviews and threat modeling for new and existing services at iHerb

  • Evaluate, prototype, implement, and operate security-focused tools and services

  • Create new secure architecture standards, frameworks and patterns spanning multiple layers

  • Discover and analyze emerging security threats, determining applicability to iHerb and proactively implement centralized mitigations

  • Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA...)

  • Maintain a strong knowledge of current security threats and operational best practices

  • Drive our security assessment, penetration testing and bug bounty programs

  • Participate in security incident response

In order to be successful in this role you must have: 

  • Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with an innate ability to translate technical vulnerabilities into organizational risks

  • 8+ years of technical security leadership at a top-tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and broader cloud computing technologies

  • Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25...)

  • Proficiency implementing SDL process, technology, and automation in a DevOps environment

  • Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption

  • Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

  • Excellent problem solving, critical thinking, collaboration and communication skills

Bonus Qualifications:

  • Experience with Cloudflare security, AWS VPCs, EC2 instances and docker

  • Ability to drive good decisions through data with great attention to detail and deliver KPIs 

  • Experience driving application security training, security champions and awareness campaigns

  • Active contributor to the security community (research, open source, publications...) with the ability to attract and hire great talent

#LI-JC1


What iHerb employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom