1

Bug Bounty Jobs in Oregon (NOW HIRING)

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

Senior Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform. * Interface with ethical hackers, triage reports, and guide product engineering teams to ...

Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep understanding of how modern systems are attacked, and how to defend against them * Experience working ...

Bug Bounty information

See Oregon salary details

$13

$22

$27

How much do bug bounty jobs pay per hour?

As of Aug 26, 2026, the average hourly pay for bug bounty in Oregon is $22.18, according to ZipRecruiter salary data. Most workers in this role earn between $18.32 and $23.37 per hour, depending on experience, location, and employer.

What is a bug bounty?

A Bug Bounty job involves finding and reporting security vulnerabilities in software, websites, or systems in exchange for monetary rewards. Companies run bug bounty programs to leverage ethical hackers' skills in identifying potential threats before malicious hackers can exploit them. Bug bounty hunters typically work as independent security researchers and submit vulnerability reports to organizations through platforms like HackerOne, Bugcrowd, or Synack. Payments vary based on the severity of the discovered flaw, with critical vulnerabilities earning the highest rewards.

What are the typical daily responsibilities of someone participating in bug bounty programs?

As a bug bounty professional, your daily activities often involve researching target applications, actively probing for vulnerabilities using automated tools and manual techniques, and documenting your findings in detailed reports. You may spend significant time reproducing and validating security issues before responsibly disclosing them to the organization via official bug bounty platforms. Collaboration is usually asynchronous, with occasional interactions with in-house security teams for clarification or follow-up on reported issues. Managing your workflow and keeping up with evolving security trends are also essential parts of the job, ensuring your findings remain thorough and relevant.

What are the key skills and qualifications needed to thrive in the bug bounty position, and why are they important?

To thrive as a Bug Bounty professional, you need a strong understanding of web application security, programming languages, and vulnerability assessment methodologies. Familiarity with tools such as Burp Suite, OWASP ZAP, and various penetration testing frameworks, as well as certifications like OSCP or CEH, is highly valued. Persistence, attention to detail, and effective written communication are essential soft skills in this role. These competencies enable professionals to discover, document, and report security flaws accurately, helping organizations improve their cyber defenses.

Can a bug bounty be a career?

A bug bounty can be a viable career path for cybersecurity professionals specializing in vulnerability research and penetration testing. Many bug bounty hunters turn their skills into full-time work by participating in programs on platforms like HackerOne or Bugcrowd, often developing expertise in specific areas and earning income through successful bug reports. However, it typically requires strong technical skills, continuous learning, and sometimes supplementary certifications to sustain a long-term career in this field.

How to become a bug bounty?

To become a bug bounty hunter, develop skills in cybersecurity, web application security, and programming languages like Python or JavaScript. Gain experience with security testing tools such as Burp Suite or OWASP ZAP, and participate in bug bounty platforms like HackerOne or Bugcrowd to practice and build a reputation.

What are the most commonly searched types of Bug Bounty jobs in Oregon?

The most popular types of Bug Bounty jobs in Oregon are:

What are popular job titles related to Bug Bounty jobs in Oregon?

For Bug Bounty jobs in Oregon, the most frequently searched job titles are:

Infographic showing various Bug Bounty job openings in Oregon as of August 2026, with employment types broken down into 74% Full Time, and 26% Contract. Highlights an 77% In-person, and 23% Remote job distribution, with an average salary of $46,136 per year, or $22.2 per hour.

Senior Product Security Engineer

OR • On-site, Remote

ClickHouse
Software Development • 51 - 200 employees

$114K - $156K/yr

Full-time

Posted 26 days ago


Job description

About the team 

The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services. 

What you will do:

  • Collaborate with engineering and product on improving existing and building new product features with focus on threat modeling, assurance and secure implementation, some examples of recent work include implementation of secure key management, passwordless authentication, m2m authentication, sandboxing and compute/network/storage isolation
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Drive implementation and usage of engineering security tools - static, dynamic code analysis, dependency checks, code licensing compliance (working knowledge of Snyk, Semgrep, GitHub CodeQL)
  • Nurture the engineering - security relationship, identify and implement process and technology improvements
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

What you bring along:

  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium, Crossplane
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Significant development and automation experience, ability to work with C++ code preferred
  • Security as code mindset, with focus on solving problems with automation and scale in mind

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)