1

Bug Bounty Program Jobs in Washington, DC (NOW HIRING)

... Program and Bug Bounty programs What are we looking for? We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

CNO Developer

Chantilly, VA · On-site

$116K - $243K/yr

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

CNO Developer

Chantilly, VA · On-site

$243K/yr

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

New

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

CNO Developer

Chantilly, VA · On-site

$243K/yr

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

New

Application Security Engineer

Washington, DC

$180K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Experience running bug-bounty, penetration testing, vulnerability scanning programs. * Experience setting up and maintaining SAST, DAST, IAST and SCA tooling * Experience using assessment tools such ...

Senior Engineer, Offensive Security

Washington, DC · On-site

$129K - $177K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

And it's a rare chance to do that hands-on inside a program that helps protect the health data of ... validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping ...

Senior Engineer, Offensive Security

Washington, DC · On-site

$129K - $177K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

And it's a rare chance to do that hands-on inside a program that helps protect the health data of ... validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping ...

Showing results 21-38

Bug Bounty Program information

See Washington, DC salary details

$18

$56

$89

How much do bug bounty program jobs pay per hour?

As of Aug 13, 2026, the average hourly pay for bug bounty program in Washington, DC is $56.18, according to ZipRecruiter salary data. Most workers in this role earn between $35.96 and $75.67 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

What are the most commonly searched types of Bug Bounty Program jobs in Washington, DC?

The most popular types of Bug Bounty Program jobs in Washington, DC are:

What are popular job titles related to Bug Bounty Program jobs in Washington, DC?

For Bug Bounty Program jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching Bug Bounty Program jobs in Washington, DC look for?

The top searched job categories for Bug Bounty Program jobs in Washington, DC are:

Infographic showing various Bug Bounty Program job openings in Washington, DC as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $116,859 per year, or $56.2 per hour.

AVP, Penetration Tester

LPL Financial

Washington, DC

Full-time

Medical, Retirement, PTO

Re-posted 6 days ago


LPL Financial rating

7.3

Company rating: 7.3 out of 10

Based on 71 frontline employees who took The Breakroom Quiz

123rd of 150 rated financial services


Job description

Where Ambition Meets Innovation

Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.

At LPL Financial, protecting our clients, advisors, and employees is foundational to everything we do. Offensive Security is a top area of investment within Information Security, and this role offers the opportunity to directly influence the security posture of a large, complex enterprise. If you enjoy handson technical work, collaborating across teams, and creatively testing the limits of modern systems, this is an exciting opportunity to help evolve LPL's offensive security capabilities.

Job Overview

As a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a primary focus on web, mobile, cloud, API, and AIenabled applications.

This individual contributor role performs advanced manual penetration testing to validate the security of company resources. The position serves as the primary point of contact for assigned testing initiatives and partners closely with stakeholders across the organization to identify security weaknesses, recommend mitigation strategies, and validate remediation efforts across LPL applications and platforms.

Responsibilities

  • Partner with product and technology stakeholders to drive endtoend penetration testing activities, including collaboration with Security Architects throughout the SDLC to identify and address security issues prior to production deployment

  • Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide actionable feedback and recommendations, including opportunities to expand automated and AIassisted testing capabilities

  • Perform security assessments of internal and external networks, infrastructure, cloud environments, and a wide range of internally developed and commercial products

  • Apply creative and analytical thinking to bypass security controls, identify vulnerabilities, and develop practical remediation guidance; stay informed on evolving tactics, techniques, and procedures (TTPs), zeroday vulnerabilities, and mitigation strategies

  • Develop or modify custom tools and scripts to support new penetration testing needs, automation, and AIassisted testing approaches

  • Document and formally report testing scope, methodology, findings, risk ratings, remediation recommendations, and validation results in a clear and concise manner

  • Present testing results to technology and business partners, clearly communicating risk, impact, and remediation guidance in an accessible and collaborative way

  • Lead execution of assigned penetration testing initiatives, including status communication to leadership and coordination with stakeholders

  • Oversee communication, tracking, and retesting of findings to validate successful closure of previously identified issues

  • Assist with validation and triage of submissions from the company's Vulnerability Disclosure Program and Bug Bounty programs

What are we looking for?

We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client experience. This role is well suited for individuals who thrive in a fastpaced environment, enjoy solving complex security challenges, and continuously look for ways to improve processes, tooling, and outcomes.

Requirements

  • 8+ years of experience conducting application, API, and networkbased penetration testing engagements

  • 6+ years of experience troubleshooting tools, manually identifying vulnerabilities in code, and rewriting code to remediate security issues

  • 3+ years of experience leading penetration testing engagements from scoping through reporting and remediation validation

  • 1+ year of experience testing AI, LLM, or Generative AIenabled applications

  • 1+ year of experience using AI models (such as Claude or similar) to accelerate tool development or testing workflows + Advanced knowledge of security assessment tools and frameworks, such as Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, MITRE ATT&CK, MITRE ATLAS, OWASP Top 10 (including OWASP Top 10 for LLMs)

Preferences

  • Bachelor's degree or equivalent experience in Information Security, Engineering, Computer Science, or a related field

  • Advanced understanding of OWASP frameworks, MITRE ATT&CK and ATLAS, and secure software development lifecycle (SDLC) practices

  • At least one industryrecognized certification, such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN

  • Advanced proficiency in one or more programming or scripting languages, such as .NET, JavaScript, Python, Java, PowerShell, Perl, Ruby, Bash, or similar

  • Advanced knowledge of Linux, macOS, and Windows operating systems, as well as AWS and Azure cloud environments and cloudnative services (e.g., containers, Kubernetes, microservices, serverless functions)

  • Experience performing reverse engineering on mobile applications, including those with obfuscation or antiemulation protections

  • Broad knowledge of operating system security, networking and protocols, firewalls, databases, middleware, forensics, and secure coding practices

  • Effective written and verbal communication skills, with the ability to collaborate with technical and nontechnical stakeholders

  • Organized approach to managing multiple testing efforts and deliverables

  • A natural curiosity for exploring, testing, and understanding security controls and how they can be improved


Pay Range:

$122,570.00 - $204,249.00
Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play - such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!

Company Overview:

LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. As a leader in the financial advisor-mediated marketplace(6) , LPL supports over 32,000 financial advisors and the wealth management practices of approximately 1,100 financial institutions, servicing and custodying approximately $2.3 trillion in brokerage and advisory assets on behalf of approximately 8 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services, ensuring that advisors and institutions have the flexibility to choose the business model, services, and technology resources they need to run thriving businesses. For further information about LPL, please visit www.lpl.com.


At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.


For further information about LPL, please visit www.lpl.com.


Join the LPL team and help us make a difference by turning life's aspirations into financial realities. Please log in or create an account to apply to this position. Principals only. EOE.


Information on Interviews:

LPL will only communicate with a job applicant directly from an@lplfinancial.comemail address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant's bank or credit card. Should you have any questions regarding the application process, please contact LPL's Human Resources Solutions Center at(855) 575-6947.


EAC 5.19.26


What LPL Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom