1

Bug Bounty Program Jobs in Atlanta, GA (NOW HIRING)

The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...

New

Senior Engineer, Offensive Security

Atlanta, GA · On-site

$110K - $151K/yr

And it's a rare chance to do that hands-on inside a program that helps protect the health data of ... validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping ...

Senior Engineer, Offensive Security

Atlanta, GA · On-site

$110K - $151K/yr

And it's a rare chance to do that hands-on inside a program that helps protect the health data of ... validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping ...

Senior Engineer, Offensive Security

Atlanta, GA · On-site

$110K - $151K/yr

And it's a rare chance to do that hands-on inside a program that helps protect the health data of ... validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping ...

Bug Bounty Program information

See Atlanta, GA salary details

$15

$47

$75

How much do bug bounty program jobs pay per hour?

As of Aug 30, 2026, the average hourly pay for bug bounty program in Atlanta, GA is $47.70, according to ZipRecruiter salary data. Most workers in this role earn between $30.53 and $64.28 per hour, depending on experience, location, and employer.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Atlanta, GA?

The most popular types of Bug Bounty Program jobs in Atlanta, GA are:

What are popular job titles related to Bug Bounty Program jobs in Atlanta, GA?

For Bug Bounty Program jobs in Atlanta, GA, the most frequently searched job titles are:

What cities near Atlanta, GA are hiring for Bug Bounty Program jobs?

Cities near Atlanta, GA with the most Bug Bounty Program job openings:

Infographic showing various Bug Bounty Program job openings in Atlanta, GA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $99,222 per year, or $47.7 per hour.

Vulnerability Analyst

Atlanta, GA


Coca-Cola
Food Services and Drinking Places • 10K+ employees

7.6

Company rating: 7.6 out of 10

Based on 442 frontline employees who took The Breakroom Quiz

141st of 443 rated food and drinks producers

People enjoy working here

Good employer

Recommended by students


Full-time

Posted 2 days ago

New


Job description

Job Description Summary:

Position Overview:

The Vulnerability Analyst is responsible for reviewing, validating, and coordinating the resolution of security vulnerabilities across The Coca-Cola Company's systems and digital assets. The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid and in scope, assigning the right owners, and tracking each issue through to a verified fix. Working closely with researchers, asset owners, and remediation teams, the Vulnerability Analyst helps ensure vulnerabilities are prioritized, addressed within established SLAs, and resolved effectively.


Function Related Activities/Key Responsibilities:

  • Review and validate incoming vulnerability reports across the VDP, BBP, and ASM programs, confirming scope and severity.

  • Coordinate remediation with asset owners and internal teams, and verify that fixes are effective before closing each report.

  • Track and prioritize vulnerabilities to ensure they are resolved within established SLAs.

  • Serve as the primary point of contact for external security researchers throughout the disclosure and resolution process.

  • Maintain accurate vulnerability records and reporting in the team's tracking platforms.


Qualifications & Experience requirements:

  • 2+ years in vulnerability management, application security, SOC, or a related security operations role.

  • Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ability to read and reproduce a proof-of-concept.

  • Demonstrated ability to validate findings, judge scope, and assess severity accurately.

  • Familiarity with vulnerability tracking / disclosure platforms and ticketing workflows.

  • Strong written communication - able to correspond with external researchers and internal owners clearly and diplomatically.

  • Preferred experience - experience running or supporting a VDP, bug bounty program or ASM function; hands-on experience with platforms such as Intigriti, HackerOne, Bugcrowd or an ASM vendor; understanding of enterprise remediation and risk-exception governance process.

The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.

Skills:

Attack Surface Analysis, Information Security, Security Vulnerability Assessments, Vulnerability Management, Vulnerability Remediation, Vulnerability Scanning

Pay Range:

United States: 107,000 - 125,700 USD

Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.

Annual Incentive Reference Value Percentage:

7.5

Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.

Location(s):

United States of America

City/Cities:

Atlanta

Travel Required:

00% - 25%

Relocation Provided:

No

Job Posting End Date:

September 4, 2026

Our Purpose and Growth Culture:

We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what's possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors - curious, empowered, inclusive and agile - and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit Our Purpose and Visionto learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.

Coca-Cola logo

About Coca-Cola

Sourced by ZipRecruiter

On May 8, 1886, Dr. John Pemberton brought his perfected syrup to Jacobs' Pharmacy in downtown Atlanta where the first glass of Coca‑Cola was poured. From that one iconic drink, we’ve evolved into a total beverage company. More than 2.2 billion servings of our drinks are enjoyed in more than 200 countries and territories each day. We are constantly transforming our portfolio, from reducing added sugar in our drinks to bringing innovative new products to market. We seek to positively impact people’s lives, communities and the planet through water replenishment, packaging recycling, sustainable sourcing practices and carbon emissions reductions across our value chain. Together with our bottling partners, we employ more than 700,000 people, helping bring economic opportunity to local communities worldwide. We are committed to offering people more of the drinks they want across a range of categories and sizes while driving sustainable solutions that build resilience into our business and create positive change for the planet.

Industry

Food services and drinking places and food and drink manufacturing

Company size

10,000+ Employees

Headquarters location

Atlanta, GA, US


What Coca-Cola employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom