1

Bug Bounty Program Jobs in Utah (NOW HIRING)

You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Bug Bounty Program information

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Utah? The most popular types of Bug Bounty Program jobs in Utah are:
What cities in Utah are hiring for Bug Bounty Program jobs? Cities in Utah with the most Bug Bounty Program job openings:
Infographic showing various Bug Bounty Program job openings in Utah as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

$67.61 - $84.51/hr

Contractor

Medical, Dental, Vision, Retirement

Re-posted 11 hours ago


Job description

Product Security Engineer
Full-time
Lehi, UT

You’ll be joining Adobe on a contract opportunity, employed through NextDeavor

 
Benefits You'll Love

NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave eligibility is contingent on state of residence Optional 401k Plan (excludes employer match) Opportunity to get your foot in the door at a well-established corporation, with potential for extended or permanent full-time employment

Become a Key Player as a Product Security Engineer

You will lead triage and validation of external vulnerability reports for the client's products, ensuring timely, accurate resolution and clear researcher communications. You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a team member on leave.

Here's How You'll Make an Impact on the Team
  • Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and scope.
  • Assign CVSS scores and severity ratings following internal guidelines and industry standards.
  • Reproduce proof-of-concept exploits across web, API, and mobile surfaces to validate reports.
  • Communicate with external researchers to request clarifications, provide status updates, and manage expectations.
  • Coordinate confirmed vulnerabilities with product engineering teams for remediation.
  • Identify duplicates, out-of-scope, or informational reports and close them with clear explanations.
  • Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
  • Flag systemic or critical findings to the Bug Bounty team for escalation.
Here's What You'll Need to Be Successful in This Role
  • 3+ years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
  • Strong understanding of CVSS v3.1 and hands-on experience applying it to real-world vulnerabilities.
  • Proficiency with common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
  • Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts.
  • Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and responsible disclosure processes.
  • Solid written communication skills for clear, constructive responses to external researchers.
  • Familiarity with attacker techniques against LLM systems and generative AI products.
  • Knowledge of OWASP Top 10 vulnerabilities and mitigation techniques.
Here's What Else Might Help You Out
  • Experience with cloud environments (AWS, Azure, GCP) and API security testing.
  • Hands-on penetration testing experience for AI/ML and LLM-powered products, including chat interfaces and inference APIs.
  • Prior participation in bug bounty programs as a researcher.
  • Familiarity with CWE taxonomy and CVE assignment processes.
  • Background working within a large enterprise or SaaS security organization.
Pay Range

$67.61 - $84.51/hour

Ready to Make Your Mark?

This role may fill quickly. Submit your resume to be considered.

Apply with Pioneers here