1

Bug Bounty Program Jobs in Raleigh, NC (NOW HIRING)

... program. Familiarity with NetApp products (e.g., ONTAP, StorageGRID) or enterprise storage/data ... Experience with bug bounty platforms (e.g., HackerOne). Education IC - Typically requires a minimum ...

Bug Bounty Program information

See Raleigh, NC salary details

$15

$48

$76

How much do bug bounty program jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for bug bounty program in Raleigh, NC is $48.22, according to ZipRecruiter salary data. Most workers in this role earn between $30.87 and $64.95 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals managing a Bug Bounty Program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a Bug Bounty Program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a Bug Bounty Program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Raleigh, NC? The most popular types of Bug Bounty Program jobs in Raleigh, NC are:
What are popular job titles related to Bug Bounty Program jobs in Raleigh, NC? For Bug Bounty Program jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Bug Bounty Program jobs in Raleigh, NC look for? The top searched job categories for Bug Bounty Program jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Bug Bounty Program jobs? Cities near Raleigh, NC with the most Bug Bounty Program job openings:
Infographic showing various Bug Bounty Program job openings in Raleigh, NC as of July 2026, with employment types broken down into 31% Locum Tenens, 43% Full Time, 5% Part Time, 1% Contract, and 20% Summer. Highlights an 89% Physical, 1% Hybrid, and 10% Remote job distribution, with an average salary of $100,298 per year, or $48.2 per hour.
Global Security PSIRT Engineer

Global Security PSIRT Engineer

NetApp

Morrisville, NC • On-site

Other

Medical, Life, Retirement, PTO

Posted 26 days ago


Job description

Job Summary

NetApp is looking for a skilled PSIRT Engineer (IC4) to join our Global Product Security Incident Response Team.
In this role, you will independently handle complex security vulnerabilities across NetApp's storage, cloud, and data management products. You will triage reports, perform technical analysis, drive fixes, and coordinate responsible disclosure.


As an IC4 engineer, you will work on high-impact issues, mentor junior team members, and help mature NetApp's PSIRT processes in alignment with ISO/IEC 30111, ISO/IEC 29147, and FIRST best practices. This is a technical, customer-focused role that directly protects NetApp customers worldwide

Job Responsibilities

Triage, verify, and conduct in-depth technical analysis of vulnerability reports from external researchers, customers, internal teams, and security tools.
Reproduce vulnerabilities in lab environments and assess risk using CVSS (v3.1/v4.0) along with NetApp-specific business and customer context.
Collaborate with engineering teams to drive root cause analysis, develop fixes, mitigations, and workarounds, and validate their effectiveness.
Manage the full vulnerability lifecycle, including embargo handling, coordinated disclosure (CVD), CVE-ID requests, and publication of Security Advisories.
Work with external stakeholders such as security researchers, CERT/CC, and other vendors for multi-party coordination.
Support proactive vulnerability monitoring, threat intelligence, third-party component tracking, and integration with the Secure Development Lifecycle (SDL).
Create clear technical documentation, customer advisories, and leadership briefings.
Mentor junior PSIRT engineers and participate in team on-call rotation.
Contribute to process improvements, tooling, metrics, and PSIRT maturity initiatives.

Job Requirements

Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent experience).
5+ years of experience in security engineering, vulnerability management, incident response, or product security.
Strong technical knowledge of operating systems (Linux/Unix), networking, storage systems, and cloud platforms (AWS, Azure, GCP).
Hands-on experience reproducing and analyzing security vulnerabilities.
Solid understanding of CVSS, CVE, CWE, responsible disclosure, and coordinated vulnerability disclosure practices.
Excellent written and verbal communication skills - able to explain complex issues clearly to both technical and non-technical audiences.
Proven ability to work independently and collaboratively in a global team environment.
Preferred Qualifications
Previous experience working in a PSIRT, Product Security, or Vulnerability Management program.
Familiarity with NetApp products (e.g., ONTAP, StorageGRID) or enterprise storage/data management technologies.
Scripting and automation skills (Python, Bash, PowerShell).
Knowledge of SBOMs, software composition analysis, and supply chain security.
Industry certifications such as CISSP, OSCP, or GIAC.
Experience with bug bounty platforms (e.g., HackerOne).

Education
IC - Typically requires a minimum of 8 years of related experience.Mgr & Exec - Typically requires a minimum of 6 years of related experience.

Compensation:
The target salary range for this position is 147,900 - 220,000 USD. The salary offered will be determined by the candidate's location, qualifications, experience, and education and may be outside of this range. The range is based on 'On Target Earnings' (OTE) representing the total potential earnings, which is the sum of the base salary and potential commission earned when performance targets are achieved. Final compensation packages are competitive and in line with industry standards, reflecting a variety of factors, and include a comprehensive benefits package. This may cover Health Insurance, Life Insurance, Retirement or Pension Plans, Paid Time Off, various Leave options, employee stock purchase plan, and/or restricted stocks (RSU's). These offerings are subject to regional variations and governed by local laws, regulations, and company policies. We will provide detailed information about the specific benefits for your region during the recruitment process.