1

Bug Bounty Jobs (NOW HIRING)

CNO Developer

Chantilly, VA · On-site

$130K - $178K/yr

... events, bug bounty programs, and speaking at the security conferences • Rapid Prototype Software Development Company : Accenture Federal Services is a leading US federal services company and ...

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you have notable skills in one or more of the following: * Web and mobile application penetration ...

Review and triage submissions from the Bug Bounty program; escalate critical findings to appropriate teams and help drive remediation * Contribute to threat modeling activities, providing expert ...

CNO Developer

Chantilly, VA · On-site

$130K - $178K/yr

... events, bug bounty programs, and speaking at the security conferences • Rapid Prototype Software Development Company : Accenture Federal Services is a leading US federal services company and ...

Senior Security Engineer - Automation

$117K - $160K/yr

We actively manage our Bug Bounty program, ensuring swift response and remediation, and leverage cutting-edge tools like Cloudflare's WAF to build robust defenses. We offer an extensive number of ...

Senior Security Engineer - Automation

New York, NY · On-site

$125K - $171K/yr

We actively manage our Bug Bounty program, ensuring swift response and remediation, and leverage cutting-edge tools like Cloudflare's WAF to build robust defenses. We offer an extensive number of ...

... bug bounty program • Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties • Collaborate with the CISO and security team to grow the broader ...

Senior Application Security Engineer

OR · Remote

$114K - $156K/yr

Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. * Own and continuously improve application ...

... our bug bounty program • Partner with engineering teams to design and deploy solutions which are inherently secure • Champion the use of tooling (linters, static analysis, posture assessment ...

Background in bug bounty programs or red teaming * Familiarity with AI or machine learning evaluation workflows Why Join Us * Work directly on cutting-edge AI projects with top research labs * Fully ...

Senior Application Security Engineer

New York, NY · Remote

$125K - $171K/yr

Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. * Own and continuously improve application ...

next page

Showing results 1-20

Bug Bounty information

See salary details

$12

$20

$25

How much do bug bounty jobs pay per hour?

As of Jun 24, 2026, the average hourly pay for bug bounty in the United States is $20.98, according to ZipRecruiter salary data. Most workers in this role earn between $17.31 and $22.12 per hour, depending on experience, location, and employer.

What does bug mean?

In the context of a bug bounty role, a bug refers to a security vulnerability or flaw in software or a website that could be exploited by attackers. Bug bounty programs reward security researchers for identifying and responsibly reporting these issues, often requiring skills in testing, analysis, and familiarity with tools like penetration testing frameworks.

What are the typical daily responsibilities of someone participating in bug bounty programs?

As a bug bounty professional, your daily activities often involve researching target applications, actively probing for vulnerabilities using automated tools and manual techniques, and documenting your findings in detailed reports. You may spend significant time reproducing and validating security issues before responsibly disclosing them to the organization via official bug bounty platforms. Collaboration is usually asynchronous, with occasional interactions with in-house security teams for clarification or follow-up on reported issues. Managing your workflow and keeping up with evolving security trends are also essential parts of the job, ensuring your findings remain thorough and relevant.

Is the movie bug worth watching?

The term 'bug' in a job context typically refers to security vulnerabilities identified during bug bounty programs. If you are interested in cybersecurity or bug bounty hunting, watching related movies can provide entertainment but may not offer practical skills. For job seekers, gaining hands-on experience with tools like Burp Suite or participating in bug bounty platforms is more valuable than movies about bugs.

What does bug mean in slang?

In slang, a 'bug' often refers to a hidden listening device or surveillance tool. In the context of bug bounty roles, it can also mean identifying software vulnerabilities or security flaws in applications or systems. Understanding this slang helps security professionals communicate effectively during penetration testing and vulnerability assessments.

What are the key skills and qualifications needed to thrive in the Bug Bounty position, and why are they important?

To thrive as a Bug Bounty professional, you need a strong understanding of web application security, programming languages, and vulnerability assessment methodologies. Familiarity with tools such as Burp Suite, OWASP ZAP, and various penetration testing frameworks, as well as certifications like OSCP or CEH, is highly valued. Persistence, attention to detail, and effective written communication are essential soft skills in this role. These competencies enable professionals to discover, document, and report security flaws accurately, helping organizations improve their cyber defenses.

What is a Bug Bounty job?

A Bug Bounty job involves finding and reporting security vulnerabilities in software, websites, or systems in exchange for monetary rewards. Companies run bug bounty programs to leverage ethical hackers' skills in identifying potential threats before malicious hackers can exploit them. Bug bounty hunters typically work as independent security researchers and submit vulnerability reports to organizations through platforms like HackerOne, Bugcrowd, or Synack. Payments vary based on the severity of the discovered flaw, with critical vulnerabilities earning the highest rewards.

What cleaners do bugs hate?

In bug bounty work, bugs are computer vulnerabilities, not insects, so cleaners are not relevant. However, in cybersecurity, certain cleaning tools like malware removal software can help eliminate malicious code, but they do not 'hate' cleaners. The focus is on identifying and fixing security flaws rather than cleaning products.
More about Bug Bounty jobs
What cities are hiring for Bug Bounty jobs? Cities with the most Bug Bounty job openings:
What are the most commonly searched types of Bug Bounty jobs? The most popular types of Bug Bounty jobs are:
What states have the most Bug Bounty jobs? States with the most job openings for Bug Bounty jobs include:
What job categories do people searching Bug Bounty jobs look for? The top searched job categories for Bug Bounty jobs are:
Senior Security Engineer, AI Vulnerability Management

Senior Security Engineer, AI Vulnerability Management

Robinhood

Menlo Park, CA • On-site

$134K - $185K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 6 days ago


Job description

Join us in building the future of finance.
Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you're ready to be at the epicenter of this historic cultural and financial shift, keep reading.
About the team + role
We are building an elite team, applying frontier technologies to the world's biggest financial problems. We're looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn't a place for complacency, it's where ambitious people do the best work of their careers. We're a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.
At Robinhood, we view security as an engineering and design challenge, not an administrative one. We are looking for a lead architect for our next-generation automated defense systems. As a Senior Vulnerability Management Engineer, you will transform the program into a self-scaling security platform that transcends traditional "scan-and-patch" cycles. You will lead the shift to an Intelligence-Driven Defense model by leveraging Agentic AI and Machine Learning to automate the discovery, prioritization, and remediation of risk at scale, ultimately making security "cheap" for our developers.
This role is based in our Menlo Park, CA office, with in-person attendance expected at least 3 days per week.
At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.
What you'll do
  • Set Strategic RBVM Vision: Act as the technical lighthouse, defining the multi-year roadmap and driving the move toward Risk-Based Vulnerability Management (RBVM), prioritizing vulnerabilities based on real-world exploitability and business context.
  • Architect Agentic AI Systems: Design and deploy AI agents that autonomously triage findings, correlate threat intelligence, and generate production-ready remediations (e.g., automated Pull Requests for dependency updates and config drift).
  • Build Exposure Intelligence: Develop systems that correlate vulnerabilities with runtime context and infrastructure topology (Kubernetes/AWS) to accurately model real-world blast radius and ensure engineers only fix what is actually exploitable.
  • Automate Triage & Self-Healing: Create "paved roads" and CI/CD guardrails that prevent specific vulnerability categories from ever reaching production, reducing manual toil for the entire engineering organization.
  • Data-Centric Visibility: Build high-fidelity dashboards using LLM-powered summarization to translate complex security signals into actionable insights for engineering leadership.
  • Lead Emergency Response: Orchestrate the technical response to high-impact zero-days by rapidly performing cross-environment blast-radius analysis.
  • Drive Execution Ownership: Take full ownership of operational security work, ensuring that critical vulnerabilities are systematically eradicated while maintaining high engineering velocity.
What you bring
  • Experience: 5+ years in Security Engineering with a track record of leading high-impact automation or security platform initiatives at a Senior or Staff level.
  • AI & Agentic System Fluency: Hands-on experience building or deploying agentic systems or LLM orchestration frameworks (e.g., LangChain, AutoGPT) to solve complex security or engineering problems at scale.
  • Bug Bounty & Exploit Proficiency: Active experience participating in or managing Bug Bounty programs; a deep understanding of how attackers exploit vulnerabilities and how to translate those findings into systemic fixes.
  • Engineering Excellence: Strong software engineering background with proficiency in Go or Python and a history of building scalable, API-driven security tooling.
  • Modern Infrastructure Depth: Deep knowledge of securing AWS and Kubernetes-based architectures.
  • Vulnerability Domain Knowledge: High familiarity with vulnerability categories, exploitability, and modern risk frameworks (CVSS, EPSS, CISA KEV).
  • Detection Ecosystems: Experience with modern platforms like Snyk, Semgrep, Wiz, EndorLabs, or TruffleHog.
  • Velocity Mindset: A commitment to reducing security friction and a track record of working effectively with high-velocity engineering teams.
Nice to have
  • Fintech Experience: Experience navigating security in highly regulated or high-growth financial environments.
  • Security as Code: Experience implementing "Security as Code" within large-scale CI/CD environments.
What we offer
  • Challenging, high-impact work to grow your career.
  • Performance-driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching.
  • Best-in-class benefits to fuel your work, including 100% paid health insurance for employees with 90% coverage for dependents.
  • Lifestyle wallet - a highly flexible benefits spending account for wellness, learning, and more.
  • Employer-paid life & disability insurance, fertility benefits, and mental health benefits.
  • Time off to recharge including company holidays, paid time off, sick time, parental leave, and more!
  • Exceptional office experience with catered meals, events, and comfortable workspaces.

In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.
Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected base pay range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones. For other locations not listed, compensation can be discussed with your recruiter during the interview process.
Base Pay Range:
Zone 1 (Menlo Park, CA; New York, NY; Bellevue, WA; Washington, DC)
$187,000-$220,000 USD
Zone 2 (Denver, CO; Westlake, TX; Chicago, IL)
$165,000-$194,000 USD
Zone 3 (Lake Mary, FL; Clearwater, FL; Gainesville, FL)
$146,000-$172,000 USD
Click here to learn more about our Total Rewards, which vary by region and entity.
If our mission energizes you and you're ready to build the future of finance, we look forward to seeing your application.
Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work-welcoming different backgrounds, perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.