1

Bug Bounty Salary Jobs (NOW HIRING)

Engineering Manager, Proactive Security

Los Angeles, CA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead the overall Security Product Engineering, Bug Bounty and Mythos era Vulnerability Management ... Base salary is localized according to an employee's work location. Ranges are market-dependent and ...

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions ... The provided salary details are based on US national averages and we retain the flexibility to ...

Software Engineer, Security

San Francisco, CA ยท On-site

$180K - $280K/yr

  • PTO

You've done some mix of vulnerability triage, bug bounty, disclosure, or incident response, and can ... Additional Job details The base salary range for this position is $180k - $280k annually.

Sr. Application Security Engineer

Redmond, WA

$170K - $235K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for ...

Senior Security Engineer

San Francisco, CA ยท On-site

$160K - $240K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Hands-on experience in offensive security (eg, through bug bounty programs or CTFs) The salary range for this role is $160,000 - $240,000. The salary for this position is determined based on a ...

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for ...

Senior Security Engineer

New York, NY ยท Hybrid

$125K - $171K/yr

The base salary offered for this role and level of experience will begin at $130,000 and go up to ... Pen testing or bug bounty experience * Familiarity with GRC tools and frameworks #LI-Hybrid #LI-JL1

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for ...

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ... These salary ranges reflect what we reasonably and in good faith believe to be the minimum and ...

Product Security Engineer

Seattle, WA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Help drive improvements across our Product Security tooling, automation, and bug bounty program ... The expected salary ranges for this position are outlined below by compensation zone and may be ...

Product Security Engineer

  • Medical

  • Dental

  • Vision

Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands ... salary. About LaunchDarkly: Modern software delivery was supposed to be the foundation for a ...

Product Security Engineer

Seattle, WA ยท On-site

$188K - $250K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Help drive improvements across our Product Security tooling, automation, and bug bounty program ... The expected salary ranges for this position are outlined below by compensation zone and may be ...

Enterprise Account Executive

Chicago, IL ยท On-site +1

$116K - $160K/yr

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions ... The provided salary details are based on US national averages and we retain the flexibility to ...

next page

Showing results 1-20

Bug Bounty Salary information

What is the typical salary or earnings for a bug bounty hunter?

The earnings for bug bounty hunters can vary widely depending on skill level, the platforms they use, and the time invested. Some hunters earn a few hundred dollars per month, while top performers can make thousands or even hundreds of thousands of dollars annually. Unlike traditional jobs, bug bounty hunting usually does not offer a fixed salary; instead, hunters are paid per valid vulnerability they report. Companies and platforms like HackerOne or Bugcrowd offer different reward amounts, which can range from $50 to over $100,000 for critical vulnerabilities. Success in this field often depends on expertise, persistence, and the ability to find high-impact bugs.

What are the key skills and qualifications needed to thrive as a bug bounty hunter, and why are they important?

To thrive as a Bug Bounty Hunter, you need strong knowledge of cybersecurity concepts, web application vulnerabilities, and penetration testing, often supported by experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and various scripting languages is crucial for identifying and exploiting security flaws. Persistence, attention to detail, and effective communication skills help you document findings and work with development teams. These abilities are vital for responsibly discovering vulnerabilities, earning rewards, and contributing to safer digital environments.

How do bug bounty hunters typically collaborate with internal security teams during vulnerability disclosure?

Bug bounty hunters often work closely with internal security teams through coordinated disclosure processes. After identifying a potential vulnerability, hunters submit detailed reports via the organization's bounty platform or disclosure channel. Security teams then triage, verify, and may request additional information from the researcher. Open communication and professionalism are key, as bounty hunters may be asked to retest fixes or clarify technical details, contributing to a collaborative, solution-oriented work environment.

What is the difference between Bug Bounty Salary vs Penetration Tester Salary?

AspectBug Bounty SalaryPenetration Tester Salary
CredentialsNone required; certifications like OSCP, CEH beneficialCertifications like OSCP, CEH, CISSP often required
Work EnvironmentRemote, freelance, project-basedFull-time, in-house or consulting roles
Employer & IndustryIndividuals, companies, organizations offering bug bountiesSecurity firms, corporations, government agencies

Bug bounty salaries are typically variable, based on rewards from organizations for discovering vulnerabilities, often freelance and project-based. Penetration testers usually have a fixed salary, working full-time in security teams or consulting firms. Both roles require cybersecurity knowledge and certifications, but bug bounty work offers more flexibility and income potential based on performance, while penetration testing provides steady employment and benefits.

Is bug bounty a good career?

Bug bounty programs offer cybersecurity professionals the opportunity to earn rewards by identifying security vulnerabilities in software and websites. It can be a viable career path for those with strong technical skills, knowledge of security tools, and the ability to work independently, often providing flexible schedules and remote work options. However, income stability varies and success depends on skill level, experience, and the number of programs participated in.
More about Bug Bounty Salary jobs

What cities are hiring for Bug Bounty Salary jobs?

Cities with the most Bug Bounty Salary job openings:

What states have the most Bug Bounty Salary jobs?

States with the most job openings for Bug Bounty Salary jobs include:

What job categories do people searching Bug Bounty Salary jobs look for?

The top searched job categories for Bug Bounty Salary jobs are:

Infographic showing various Bug Bounty Salary job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Product Security Engineer (PSIRT - Product Security Incident Response Team)

Replit

Foster City, CA โ€ข On-site

Other

Medical, Dental, Vision, Life, Retirement

Re-posted 28 days ago


Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit's cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services-from intake to validation, remediation coordination, and public disclosure.
This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly.
What You'll Do
Vulnerability Intake, Triage & Validation
  • Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
  • Independently validate, reproduce, severity-score, and document findings.
  • Identify duplicates and maintain a clean vulnerability records pipeline.
  • Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
Remediation Coordination & SLA Management
  • Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
  • Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
  • Track SLAs, remediation progress, regression testing, and systemic improvements.
  • Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
Bug Bounty & Vulnerability Disclosure Program Management
  • Design and evolve the bug bounty program, including scope, rules, and reward structures.
  • Manage platform selection, private vs. public launches, and community engagement.
  • Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
  • Determine reward payouts, bonus decisions, and recognition for top contributors.
Coordinated Disclosure & CVE Management
  • Lead the coordinated vulnerability disclosure process for internal and external findings.
  • Negotiate disclosure timelines with researchers and partners.
  • Coordinate CVE assignments and publications, and prepare customer/public advisories.

Required Skills
  • Experience running or triaging for bug bounty programs (HackerOne ideally).
  • Strong ability to triage, validate, and reproduce vulnerabilities independently.
  • Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
  • Familiarity with cloud platforms (Google Cloud Platform preferred) and SaaS architectures.
  • Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.

Nice to Have
  • Scripting or automation experience (Python, Go, Bash).
  • Pentesting background or exposure to offensive security work.
  • Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
  • Experience authoring public advisories or CVE writeups.
  • Hands-on experience with SIEM, Cloud Logging, and investigative tooling.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
Competitive Salary & Equity
? 401(k) Program with a 4% match (US Only)
Health, Dental, Vision and Life Insurance
Short Term and Long Term Disability
Paid Parental, Medical, Caregiver Leave
Flexible Time Off (FTO) + Holidays
Commuter Benefits (In-Office & US Only)
Monthly Wellness Stipend
Autonomous Work Environment
In Office Set-Up Reimbursement (In-Office Only)
Quarterly Team Gatherings
In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Meet the Replit Agent
  • Replit: Make an app for that
  • Replit Blog
  • Amjad TED Talk

Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.