1

Bug Bounty Program Jobs (NOW HIRING)

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

... our bug bounty program end to end: triage, response, remediation, and researcher communication • Partner with Engineering to embed secure design patterns and security review into how we ship ...

CNO Developer

Chantilly, VA · On-site

$129K - $177K/yr

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

Build the automation that triages, routes, and reports vulnerability findings, and run our enterprise Bug Bounty program. * Operate and improve Bot Management, WAF, secrets management, and API ...

Software Security Engineer

Pittsburgh, PA · On-site

$110K - $120K/yr

Build the automation that triages, routes, and reports vulnerability findings, and run our enterprise Bug Bounty program. * Operate and improve Bot Management, WAF, secrets management, and API ...

Security Manager

San Francisco, CA · On-site

$120K - $200K/yr

Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting * Coordinate vulnerability remediation across security vendors ...

CNO Developer

Chantilly, VA · On-site

$130K - $178K/yr

... events, bug bounty programs, and speaking at the security conferences • Rapid Prototype Software Development Company : Accenture Federal Services is a leading US federal services company and ...

... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...

Showing results 41-60

Bug Bounty Program information

See salary details

$16

$49

$78

How much do bug bounty program jobs pay per hour?

As of Aug 6, 2026, the average hourly pay for bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

More about Bug Bounty Program jobs
What cities are hiring for Bug Bounty Program jobs? Cities with the most Bug Bounty Program job openings:
What are the most commonly searched types of Bug Bounty Program jobs? The most popular types of Bug Bounty Program jobs are:
What states have the most Bug Bounty Program jobs? States with the most job openings for Bug Bounty Program jobs include:
What job categories do people searching Bug Bounty Program jobs look for? The top searched job categories for Bug Bounty Program jobs are:
Infographic showing various Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Staff+ Security Engineer, Developer Tools

Verkada

San Mateo, CA • On-site

Full-time

Re-posted 18 days ago


Job description

Job Summary:
Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform. They are seeking a Staff Security Engineer to collaborate with the Developer Experience engineering team, performing threat models, security design reviews, and refining security tools throughout the software development lifecycle.
Responsibilities:
• Facilitate the security baked into our applications throughout the software development lifecycle
• Evangelize software security best practices through training and information sharing
• Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed customers’ expectations
• Explore innovative solutions to enable Verkada business instead of “Security says No”
• Collaborate with other engineering leaders to define, communicate, and execute on goals, priorities and process
• Set up security tooling and secure defaults to ensure software security best practices
• Perform architecture analysis, threat modeling and technical design reviews of sensitive features and infrastructure
• Create and operate a bug bounty program
• Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties
• Collaborate with the CISO and security team to grow the broader Verkada security program
• Share your security experience with other teams internally and externally via security conferences and blogs
• Help your peer engineers grow their own security reasoning and knowledge
Qualifications:
Required:
• Bachelor of Science in Computer Science degree or equivalent
• Strong experience with AWS, GCP or other cloud service provider
• 7+ years of experience as a security engineer, software engineer, site reliability engineer, or security consultant
• Understanding of security weaknesses, exploits, attacks and mitigations
• Experience and enthusiasm for learning about new security products, features, and strategies
• Coding ability. You will sometimes write production Python/Go code, security peer review code, build proofs of concept or implement automation scripts
• Excellent collaborative skills
• Outstanding written and verbal communication
• Experience with most of the following: Security Development Lifecycle, Threat Modeling, Architecture Analysis, Technical Design Review, Security Code Review, Open Policy Agent, SIEM
Company:
Verkada is a cyber security company that offers an AI integrated platform for cloud physical security. Founded in 2016, the company is headquartered in San Mateo, USA, with a team of 1001-5000 employees. The company is currently Late Stage.