1

Bug Bounty Program Jobs in Texas (NOW HIRING)

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Cybersecurity Engineer

Houston, TX · On-site

$85 - $130/hr

Support application security efforts and assist with the bug bounty and responsible disclosure program, including vulnerability triage and researcher communications. * Evaluate AI-powered tools and ...

Manager, Offensive Security

Austin, TX · On-site

$110K - $148K/yr

Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations. * Experience partnering with development teams to improve secure design, detection, and resilience ...

AVP, Penetration Tester

Charlotte, TX · On-site

$122.57 - $204.25/hr

... Bug Bounty programs Requirements * 8+ years of experience conducting application, API, and network‑based penetration testing engagements * 6+ years of experience troubleshooting tools, manually ...

... Program and Bug Bounty programs What are we looking for? We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client ...

Engineering Manager, Application Security

Austin, TX · On-site

$58.25 - $77.75/hr

... automated pen-testing program. Stand up pipelines that run continuous, AI-assisted offensive ... Design the workflows and tooling that let the team handle 10x the volume of findings (bug bounty ...

... bug bounty, and threat intelligence. Establish a common exposure taxonomy and risk model that ... Develop security champions programs across engineering organizations. Leadership Lead, mentor, and ...

Director Application Security

Austin, TX · On-site

$58.25 - $77.75/hr

... bug bounty, and threat intelligence. * Establish a common exposure taxonomy and risk model that ... Develop security champions programs across engineering organizations. Leadership * Lead, mentor ...

next page

Showing results 1-20

Bug Bounty Program information

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Texas?

The most popular types of Bug Bounty Program jobs in Texas are:

What are popular job titles related to Bug Bounty Program jobs in Texas?

For Bug Bounty Program jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Bug Bounty Program jobs in Texas look for?

The top searched job categories for Bug Bounty Program jobs in Texas are:

What cities in Texas are hiring for Bug Bounty Program jobs?

Cities in Texas with the most Bug Bounty Program job openings:

Infographic showing various Bug Bounty Program job openings in Texas as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Senior Product Security Engineer

Jobtailor

Austin, TX • On-site

$190 - $240/hr

Other

Posted 11 days ago


Job description

Responsibilities
  • Autonomously Drive AI Security Innovation: Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling: Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management: Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support: Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship: Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.
Requirements
  • Senior-Level Product/AppSec Expertise: Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools . Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis: Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership: Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication: Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.
Core Competencies

Demonstrates extensive expertise in Product and Application Security, with a strong focus on AI-driven solutions and vulnerability management within large-scale distributed cloud environments. Proven ability to lead security architecture initiatives, mentor engineering teams, and influence cross-functional stakeholders effectively.

Highest-signal resume keywords
  • Product/Application Security Expertise
  • AI & Automation Engineering
  • Threat Modeling Methodologies
  • Vulnerability Lifecycle Management
  • Cross-Functional Leadership
ATS Optimization KeywordsHard Skills
  • AI-Driven Solutions
  • Code Analysis Automation
  • Threat Modeling
  • Vulnerability Management
  • Penetration Testing
  • Automation Scripts
  • Risk Analysis
  • Security Architecture
  • Cloud Environments
  • SaaS Platforms
Soft Skills
  • Influence
  • Mentorship
  • Communication
  • Leadership
  • Collaboration
Industry Keywords
  • Bug Bounty Program
  • Security Workflows
  • Engineering Ownership
  • SLAs
  • Distributed Systems
#J-18808-Ljbffr