1

Bug Bounty Jobs (NOW HIRING)

About the Role: We're looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty ...

Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions

In this role, you will be the "Architect of the Signal," building the platform that turns a flood of raw test results, including vulnerability scans, penetration tests (J5), and bug bounty/VDP ...

Senior Security Engineer - Product Security

$117K - $160K/yr

You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...

Senior Security Engineer - Product Security

$117K - $160K/yr

You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...

In this role, you will be the "Architect of the Signal," building the platform that turns a flood of raw test results, including vulnerability scans, penetration tests (J5), and bug bounty/VDP ...

NY · On-site

$54.25 - $72.50/hr

Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. * Collaborate with Dev/QA teams throughout the ...

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions. * Familiarity with Salesforce and sales engagement tools. * A four-year degree from an accredited ...

$43.25 - $58/hr

SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs. * Partner with DevOps and engineering ...

$84K - $115K/yr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

Director Application Security

Austin, TX · On-site

$58.25 - $77.75/hr

SAST, DAST, SCA, IAST, API security testing, container security, IaC security, secure code review, and coordinate penetration testing and bug bounty programs. * Partner with DevOps and engineering ...

Showing results 41-60

Bug Bounty information

See salary details

$12

$20

$25

How much do bug bounty jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for bug bounty in the United States is $20.98, according to ZipRecruiter salary data. Most workers in this role earn between $17.31 and $22.12 per hour, depending on experience, location, and employer.

What is a bug bounty?

A Bug Bounty job involves finding and reporting security vulnerabilities in software, websites, or systems in exchange for monetary rewards. Companies run bug bounty programs to leverage ethical hackers' skills in identifying potential threats before malicious hackers can exploit them. Bug bounty hunters typically work as independent security researchers and submit vulnerability reports to organizations through platforms like HackerOne, Bugcrowd, or Synack. Payments vary based on the severity of the discovered flaw, with critical vulnerabilities earning the highest rewards.

What are the typical daily responsibilities of someone participating in bug bounty programs?

As a bug bounty professional, your daily activities often involve researching target applications, actively probing for vulnerabilities using automated tools and manual techniques, and documenting your findings in detailed reports. You may spend significant time reproducing and validating security issues before responsibly disclosing them to the organization via official bug bounty platforms. Collaboration is usually asynchronous, with occasional interactions with in-house security teams for clarification or follow-up on reported issues. Managing your workflow and keeping up with evolving security trends are also essential parts of the job, ensuring your findings remain thorough and relevant.

What are the key skills and qualifications needed to thrive in the bug bounty position, and why are they important?

To thrive as a Bug Bounty professional, you need a strong understanding of web application security, programming languages, and vulnerability assessment methodologies. Familiarity with tools such as Burp Suite, OWASP ZAP, and various penetration testing frameworks, as well as certifications like OSCP or CEH, is highly valued. Persistence, attention to detail, and effective written communication are essential soft skills in this role. These competencies enable professionals to discover, document, and report security flaws accurately, helping organizations improve their cyber defenses.

Can a bug bounty be a career?

A bug bounty can be a viable career path for cybersecurity professionals specializing in vulnerability research and penetration testing. Many bug bounty hunters turn their skills into full-time work by participating in programs on platforms like HackerOne or Bugcrowd, often developing expertise in specific areas and earning income through successful bug reports. However, it typically requires strong technical skills, continuous learning, and sometimes supplementary certifications to sustain a long-term career in this field.

How to become a bug bounty?

To become a bug bounty hunter, develop skills in cybersecurity, web application security, and programming languages like Python or JavaScript. Gain experience with security testing tools such as Burp Suite or OWASP ZAP, and participate in bug bounty platforms like HackerOne or Bugcrowd to practice and build a reputation.
More about Bug Bounty jobs

What cities are hiring for Bug Bounty jobs?

Cities with the most Bug Bounty job openings:

What are the most commonly searched types of Bug Bounty jobs?

The most popular types of Bug Bounty jobs are:

What states have the most Bug Bounty jobs?

States with the most job openings for Bug Bounty jobs include:

Infographic showing various Bug Bounty job openings in the United States as of September 2026, with employment types broken down into 69% Full Time, and 31% Contract. Highlights an 54% In-person, and 46% Remote job distribution, with an average salary of $43,637 per year, or $21 per hour.

Staff+ Application Security Engineer - M&A

Seattle, WA • On-site

$67 - $89.50/hr

Other

Posted 26 days ago


Key responsibilities

  • Lead pre-close security due diligence on prospective acquisitions, including coordinating external penetration testing, threat modeling, and assessing security controls.

  • Drive post-close security integration by establishing analysis coverage, tracking remediation, and onboarding acquired assets into security systems.

  • Coordinate with various security and engineering teams, and communicate security findings and plans to stakeholders across different functions.


Job description

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic's Application Security team secures the systems that build, serve, and increasingly are Claude — and as Anthropic's footprint grows, that mandate now extends to companies and codebases we bring in from outside. This role establishes that function.

You'll own security due diligence and secure integration for Anthropic's acquisitions — assessing a target's security posture pre-close, writing the security risk readout for leadership, and after close, bringing acquired systems up to Anthropic's bar. Security has been part of every deal to date, but this is the first dedicated role for it: you'll formalize the playbook, the risk model, and the tooling, and make them repeatable.

This is an AppSec role first. You'll be an active member of the Application Security team — same rituals, same on-run rotation, same tooling, working alongside engineers securing Anthropic's own agentic product surfaces. The expectation is the same too: we use Claude as our primary tool, and you're expected to automate the repeatable parts of diligence and integration as you go, so each acquisition is easier than the last. When deal flow is quiet, you'll pick up core AppSec project work; when it's active, M&A is your priority.

We're upfront that the center of gravity here is M&A rather than core product security. It's burstier, more assessment-heavy, and operates on confidential, time-sensitive work. If you like parachuting into an unfamiliar codebase under time pressure and turning it into a clear risk picture for leadership, this is that job.

Key responsibilities
  • Lead pre-close security due diligence on prospective acquisitions — coordinate external penetration testing, threat-model the target's architecture, assess security controls, and deliver the security risk readout for leadership ahead of close and integration planning
  • Drive post-close security integration — stand up static and dynamic analysis coverage on acquired codebases, track high- and critical-severity remediation to closure, fold acquired assets into bug bounty scope, and onboard repositories to Anthropic's automated vulnerability remediation and reporting systems
  • Coordinate adjacent security engineering teams (supply chain, cloud, corporate security, detection & response) on their portions of each integration
  • Work across a wide set of stakeholders on every deal — corporate development, legal, security leadership, and the engineering teams inheriting acquired systems internally; engineering and security counterparts at the target company externally — translating between them and keeping the security workstream legible to all of them
  • Formalize and scale Anthropic's M&A security playbook — risk-scoring model, diligence runbook, integration checklist — and turn as much of it as possible into Claude-powered tooling rather than manual process
  • Share the team's operational on-run rotation (bug bounty escalations, launch consults, incident response), swapping out during periods of active deal work
  • Contribute to core AppSec projects between deals — secure design reviews, threat modeling for agentic systems, and the team's security automation roadmap
Minimum qualifications
  • Hands-on application and infrastructure security experience, including cloud and containerized environments
  • Demonstrated ability to rapidly assess an unfamiliar codebase or architecture and produce a clear, prioritized risk assessment for a non-security audience
  • Production-quality coding ability in at least one of Python, Go, Rust, or TypeScript
  • Practical threat-modeling and vulnerability-identification skills — you've found and reasoned about real bugs in real systems
  • Comfort operating with high autonomy, ambiguity, and tightly-held confidential context
  • Clear written and verbal communication across varied audiences — executives, legal and corporate development partners, and engineering counterparts at an acquired company
Preferred qualifications
  • 7+ years in application security, security consulting, or security architecture
  • Prior M&A security due diligence, third-party security assessment, or technical due diligence experience
  • Experience standing up or scaling SAST/DAST, bug bounty, or vulnerability management coverage across multiple codebasesTrack record of building security automation or tooling rather than relying solely on manual review
  • Familiarity with using LLMs as a core part of your security workflow
  • Experience securing agentic, code-execution, or LLM-integrated systems
Representative projects
  • Point Anthropic's internal LLM-driven code analysis and AI-assisted scanning at an acquired repository nobody here has seen, and turn the output into a prioritized remediation plan in days rather than weeks
  • Design the risk-scoring framework Anthropic uses to compare security posture across acquisitions of different shapes and sizes
  • Build the automation that onboards an acquired codebase to Anthropic's vulnerability dashboard, dependency auto-patching, and bounty scope without a human running a checklist
  • Write the security risk memo for a live deal and present it to corporate development and security leadership
Compensation

Annual Salary: $320,000 — $485,000 USD

Logistics

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

#J-18808-Ljbffr