1

Bug Bounty Jobs (NOW HIRING)

You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for ...

New

Operate the bug bounty program, triage vulnerability reports, and coordinate responses. * Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and ...

New

Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives * AI/LLM Probing: Perform initial prompt injection and jailbreak ...

Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...

$208 - $312/hr

Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...

Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives * AI/LLM Probing: Perform initial prompt injection and jailbreak ...

Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security Automation : Develop and implement ...

$150 - $170/hr

Bug Bounty Program*** Oversee day-to-day operation of the bug bounty program, including program scope, policy, response targets, and researcher communications.* Triage inbound submissions: reproduce ...

Bug Bounty Triage: Perform the technical triage and validation of Cloudflare's external Bug Bounty submissions, verifying exploitability and evaluating business risk. * Pentest Coordination: Support ...

Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human ...

Showing results 21-40

Bug Bounty information

See salary details

$12

$20

$25

How much do bug bounty jobs pay per hour?

As of Aug 24, 2026, the average hourly pay for bug bounty in the United States is $20.98, according to ZipRecruiter salary data. Most workers in this role earn between $17.31 and $22.12 per hour, depending on experience, location, and employer.

What is a bug bounty?

A Bug Bounty job involves finding and reporting security vulnerabilities in software, websites, or systems in exchange for monetary rewards. Companies run bug bounty programs to leverage ethical hackers' skills in identifying potential threats before malicious hackers can exploit them. Bug bounty hunters typically work as independent security researchers and submit vulnerability reports to organizations through platforms like HackerOne, Bugcrowd, or Synack. Payments vary based on the severity of the discovered flaw, with critical vulnerabilities earning the highest rewards.

What are the typical daily responsibilities of someone participating in bug bounty programs?

As a bug bounty professional, your daily activities often involve researching target applications, actively probing for vulnerabilities using automated tools and manual techniques, and documenting your findings in detailed reports. You may spend significant time reproducing and validating security issues before responsibly disclosing them to the organization via official bug bounty platforms. Collaboration is usually asynchronous, with occasional interactions with in-house security teams for clarification or follow-up on reported issues. Managing your workflow and keeping up with evolving security trends are also essential parts of the job, ensuring your findings remain thorough and relevant.

What are the key skills and qualifications needed to thrive in the bug bounty position, and why are they important?

To thrive as a Bug Bounty professional, you need a strong understanding of web application security, programming languages, and vulnerability assessment methodologies. Familiarity with tools such as Burp Suite, OWASP ZAP, and various penetration testing frameworks, as well as certifications like OSCP or CEH, is highly valued. Persistence, attention to detail, and effective written communication are essential soft skills in this role. These competencies enable professionals to discover, document, and report security flaws accurately, helping organizations improve their cyber defenses.

Can a bug bounty be a career?

A bug bounty can be a viable career path for cybersecurity professionals specializing in vulnerability research and penetration testing. Many bug bounty hunters turn their skills into full-time work by participating in programs on platforms like HackerOne or Bugcrowd, often developing expertise in specific areas and earning income through successful bug reports. However, it typically requires strong technical skills, continuous learning, and sometimes supplementary certifications to sustain a long-term career in this field.

How to become a bug bounty?

To become a bug bounty hunter, develop skills in cybersecurity, web application security, and programming languages like Python or JavaScript. Gain experience with security testing tools such as Burp Suite or OWASP ZAP, and participate in bug bounty platforms like HackerOne or Bugcrowd to practice and build a reputation.
More about Bug Bounty jobs

What cities are hiring for Bug Bounty jobs?

Cities with the most Bug Bounty job openings:

What are the most commonly searched types of Bug Bounty jobs?

The most popular types of Bug Bounty jobs are:

What states have the most Bug Bounty jobs?

States with the most job openings for Bug Bounty jobs include:

Infographic showing various Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $43,637 per year, or $21 per hour.

Senior Security Engineer - Product Security

TaxSlayer

Evans, GA

$96K - $132K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

Senior Security Engineer- Product Security

Augusta, Ga

Work Location & Schedule

This is a hybrid position based in our Augusta, GA office. Team members are expected to work on-site two days per week in our Augusta office and remotely three days per week. This schedule supports collaboration while offering flexibility and work-life balance.
For the right candidate, this position may also be considered as a fully remote opportunity for individuals residing in Georgia, South Carolina, North Carolina, Florida, or Tennessee only.

Who we are:

At TaxSlayer, we're more than just a tax software development company; we’re empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease. As a leading innovator in tax prep software, TaxSlayer, LLC, has been revolutionizing the way people file their taxes since 1965. Our user-friendly platform offers an intuitive interface that guides customers through the tax-filing process step by step, ensuring accuracy and maximum refunds.

TaxSlayer is headquartered in Augusta, GA with a satellite office in Charlotte, NC. TaxSlayer proudly employs nearly 200 individuals year-round, plus 300 additional in-season support agents. Our employees are among the brightest, most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season.

Are you a TaxSlayer?

About the Role

The Senior Security Engineer – Product Security serves as the primary security partner to software development teams, helping ensure security is embedded throughout the software development lifecycle. This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk management initiatives. Working closely with engineering, product, and Information Security teams, this position helps protect sensitive taxpayer and financial data while fostering secure development practices across the organization.

Core Responsibilities

  • Serve as the primary security point of contact for assigned Development teams, participating in sprint planning, architecture discussions, and design reviews.
  • Review product features, system designs, APIs, authentication mechanisms, and third-party integrations to identify and mitigate security risks.
  • Partner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practices.
  • Conduct secure code reviews, threat modeling activities, architecture risk assessments, and security testing for applications and product releases.
  • Perform hands-on penetration testing and coordinate third-party testing efforts when appropriate.
  • Manage and optimize SAST, DAST, and CI/CD security tooling and processes.
  • Track identified vulnerabilities through remediation and collaborate with engineering teams to address findings.
  • Own day-to-day administration of the company's bug bounty program, including researcher engagement, submission triage, validation, and remediation coordination.
  • Monitor and report bug bounty program performance metrics and recommend process improvements.
  • Support governance, risk, and compliance initiatives, including audits and assessments related to PCI DSS, SOC 2, IRS security requirements, and other applicable regulations.
  • Contribute to enterprise risk management activities and maintain product-level security risk documentation.
  • Assist with security incident response activities, including investigation, root cause analysis, and remediation tracking.
  • Mentor engineering teams on secure coding practices, threat modeling, and product security best practices.
  • Other duties as assigned.

How your Success is measured

  • Reduction in application and product security vulnerabilities identified in production environments.
  • Timely completion of security reviews, threat models, and vulnerability remediation activities.
  • Effective integration of security controls within the software development lifecycle.
  • Successful management and continuous improvement of the bug bounty program, including response and remediation timelines.
  • Positive audit and compliance assessment outcomes related to product security controls.
  • Increased adoption of secure coding practices and security standards across development teams.
  • Clear communication of technical risks and effective collaboration with engineering and business stakeholders.

Education & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent combination of education and experience.
  • Minimum of 5 years of experience in application security, product security, security engineering, or a related field.
  • Experience partnering closely with software development teams to integrate security into the development lifecycle.
  • Experience identifying and validating vulnerabilities in web applications, APIs, and cloud-based environments.

Skills & Competencies

  • Strong knowledge of secure software development lifecycle (SDLC) practices.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Knowledge of common vulnerability frameworks including OWASP Top 10 and CWE/SANS Top 25.
  • Experience with SAST, DAST, penetration testing, code review, and CI/CD security tools.
  • Strong understanding of web application, API, and cloud security principles.
  • Ability to assess and communicate technical security risks to technical and non-technical audiences.
  • Strong problem-solving, collaboration, and relationship-building skills.
  • Ability to balance security requirements with business objectives and product delivery schedules.
  • Preferred certifications include OSCP, OSWE, GWAPT, CSSLP, or comparable credentials.
  • Experience with bug bounty or vulnerability disclosure programs is strongly preferred.
  • Familiarity with regulatory frameworks including PCI DSS, SOC 2, FTC Safeguards Rule, IRS security requirements, CCPA, and related standards is preferred.

Physical & Work Environment Requirements

  • This is a hybrid or remote role.
  • Work is performed in a standard office environment with minimal physical demands.
  • Must be able to work at a computer for extended periods.
  • Occasional travel may be required for meetings, training, or business needs.
Ready to Join Us?

Apply today and be sure to opt in for text updates to stay connected with our recruiting team throughout the process!


What We Offer

At TaxSlayer, we know that our greatest strength lies in the talented individuals who drive our innovation and success. That’s why we’re proud to offer a competitive, comprehensive, and flexible benefits package designed to support your well-being, growth, and work-life balance.

Flexible Work Options
Enjoy remote and hybrid work opportunities, depending on the role and team needs.

Generous Time Off
Full Time employees receive a robust PTO bank, plus paid holidays to recharge and refresh.

Health & Wellness Coverage

  • Medical, Dental, and Vision insurance through Aetna and SunLife
  • Coverage options include: Employee Only, Employee + Spouse/Domestic Partner, Employee + Children, or Family
  • Access to a Wellness Program and on-site fitness facility

Financial Benefits

  • 401(k) with a 150% match on up to 3% of your contribution
  • Performance-based bonuses and regular salary reviews

Additional Perks

  • Company-paid life insurance, short-term and long-term disability
  • Optional critical illness and accident insurance
  • Education assistance to support your professional development
  • Company-paid parking, company store, and unlimited free coffee

Please note: As a federal contractor, we are responsible to ensure our employees meet any obligations set forth by the U.S. government. We will inform you of any applicable requirements as they arise.

Legal Disclaimers TaxSlayer is an equal opportunity employer and complies with all applicable laws regarding discrimination. Employment is based on qualifications, merit, and business need. This job description is not intended to be all-inclusive and may be subject to change to meet business needs.