1

Bug Bounty Program Jobs in Oregon (NOW HIRING)

OR

$114K - $156K/yr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security Automation : Develop and implement ...

Coordinate with third-party security vendors for external assessments and bug bounty program management where applicable. Security Engineering * Own remediation follow-through: translate pen test ...

Coordinate with third-party security vendors for external assessments and bug bounty program management where applicable. Security Engineering * Own remediation follow-through: translate pen test ...

Principal Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

Drive our security assessment, penetration testing and bug bounty programs * Participate in security incident response In order to be successful in this role you must have: * Demonstrated technical ...

OR

$180K - $225K/yr

Triage Bug Bounty findings and responsibility disclosed vulnerabilities. * Able to participate in ... Running a Security Champions program. * Open Source automation or automation projects. * Expertise ...

Senior Offensive Security Engineer

OR · On-site +1

$114K - $156K/yr

... program and encourage participation. * Receive and triage vulnerability reports submitted by external researchers through various channels, such as email, web form, or bug bounty platform.

Strong experience with code review, security reviews, security architecture, pentesting, and bug bounty programs * Experience working in full-stack projects * Experience with discovering and fixing ...

OR

$114K - $156K/yr

... coordination, bug bounty intake, and prioritization of findings into durable engineering ... Experience leading security engineering programs in at least two of the following domains ...

Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep ... Holistic perks program (including free therapy, employee wellness, and more) * Excellent health ...

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Oregon? The most popular types of Bug Bounty Program jobs in Oregon are:
What job categories do people searching Bug Bounty Program jobs in Oregon look for? The top searched job categories for Bug Bounty Program jobs in Oregon are:

$114K - $156K/yr

Full-time

Posted 8 days ago


Job description

About the team 

The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services. 

What you will do:

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL)
  • Nurture the engineering - security relationship, identify and implement process and technology improvements
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

What you bring along:

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium, Crossplane
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Significant development and automation experience, ability to work with C++ code preferred
  • Security as code mindset, with focus on solving problems with automation and scale in mind

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)