1

Contract Bug Finding Jobs (NOW HIRING)

Renewal of this contract for the following fiscal year (or a portion thereof) may be granted at the ... Problem-solving, troubleshooting, and bug fixing using web services, APIs, XML, REST, SOAP, WSDL ...

Senior Application Security Engineer

$60.25 - $80.25/hr

Drive findings to closure at the class level, fix a token-handling bug once at the platform layer ... Code (yours), Infrastructure & Contract, Behavioral Intelligence, Adversarial Simulation, and Data ...

... a finding. That chain is short and real. The interface is the throughput. The other half is harder ... A versioned sparse-RLE mask contract keyed by SOP Instance UID, and the math that scales a 512 ...

$113K - $237K/yr

Proven track record of finding vulnerabilities in distributed systems, virtualization layers, or ... Experience with automated bug-hunting techniques, including fuzzing and symbolic/concolic execution.

New

Agentic Software Test Engineer

La Crosse, WI · On-site

$97.41 - $135.83/hr

Author the prompts, context contracts, and knowledge bases** that drive the agents through test ... Build evaluation harnesses** that measure agent output quality -- false-positive rates on bug ...

Showing results 21-40

Contract Bug Finding information

See salary details

$41K

$106K

$139K

How much do contract bug finding jobs pay per year?

As of Sep 2, 2026, the average yearly pay for contract bug finding in the United States is $106,034.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $119,000.00 per year, depending on experience, location, and employer.

What cities are hiring for Contract Bug Finding jobs?

Cities with the most Contract Bug Finding job openings:

What are the most commonly searched types of Bug Finding jobs?

The most popular types of Bug Finding jobs are:

What states have the most Contract Bug Finding jobs?

States with the most job openings for Contract Bug Finding jobs include:

Application Security Engineer, Frontier AI Evaluation (Contract)

Cobalt

Santa Rosa, CA • On-site

$64.25 - $85.75/hr

Other

Posted 3 days ago

New


Job description

About the role:

Cobalt is seeking application security engineers to produce the expert reasoning and evaluation data used to train and assess frontier AI models on secure code: writing it, reviewing it, and fixing it.

This opportunity is suited to engineers who sit between security and software development: application and product security engineers, secure code reviewers, security-focused senior engineers, and consultants who do source-level assessments rather than only network testing.

You do not need prior experience in data annotation or AI research. What matters is that you can read unfamiliar code, see the vulnerability class before the scanner does, and articulate why a given fix is correct rather than merely sufficient to close the ticket.

All work is performed against sandboxed environments, purpose-built targets, and model endpoints supplied by us or by the lab. We do not accept work performed against systems you are not authorized to test, and we do not accept material covered by a client agreement or obtained without authorization.


What you'll do:

Depending on the project, you may:

  • Produce written review traces on real code, capturing how you orient in an unfamiliar codebase, which paths you follow, what you rule out and why, and how you confirm a finding is exploitable rather than theoretical
  • Author paired secure and insecure implementations, along with the tests and exploit conditions that distinguish them
  • Evaluate model-generated code and remediations, ranking solutions, explaining what makes the stronger one stronger, and identifying fixes that close the report without closing the underlying flaw
  • Assess whether a proposed fix introduces regressions, breaks intent, or shifts the vulnerability elsewhere, and identify results that pass tests but remain unsafe
  • Design rubrics and partial-credit criteria for scoring multistep review and remediation tasks, and classify findings into a consistent taxonomy

Projects follow their own guidelines, scope rules, and quality standards, and you will work with feedback from reviewers and lab research teams.


Required qualifications:

  • Demonstrable application security experience, evidenced by professional secure code review or assessment work, published research, a substantive bug bounty record in software targets, or comparable work
  • Strong software engineering ability in at least one of Python, TypeScript or JavaScript, Go, Rust, Java, C, or C++, and comfort reading unfamiliar codebases across more than one language
  • Depth in at least one area, for example web and API security, authentication and authorization design, cryptographic implementation, dependency and supply chain security, or cloud and infrastructure as code
  • Ability to explain each step of your reasoning clearly in writing, at a level another engineer could act on in a pull request
  • Willingness to work strictly within defined scope and authorization, and to sign a confidentiality agreement covering project materials


Why join Cobalt AI:

  • Advance frontier AI where it counts. Apply your security expertise to data that frontier labs cannot obtain any other way, where your judgment directly shapes how the next generation of models reasons about security.
  • Grow professionally. Expand your influence through evaluation projects, advisory roles, and research collaborations, while developing a working understanding of how frontier models are trained and assessed.
  • Work with a top-tier network. Collaborate with security engineers and researchers from leading organizations on high-impact, flexible work.
  • Set your own schedule. Flexible 10 to 40 hour weeks that fit around your existing engagements and your life.
  • Competitive pay. Rates vary by project and are determined by a number of factors, including scope, skillset, and experience.