2

Entry Level Bug Bounty Program Jobs (NOW HIRING)

Have a background in QA automation, AppSec, API/security/pen testing, or bug bounty. * Have strong ... A track record in CTFs, red-team competitions, or responsible-disclosure / bounty programs. Why ...

You'll bring depth in security fundamentals and program design as a member of a small, high ... Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.

... bug bounty programs, public research, blogging, presentations, etc.) • Experience with big data and relational databases (Hive, Presto, MySQL, etc.) • Experience with offensive testing of at ...

New

You'll bring depth in security fundamentals and program design as a member of a small, high ... Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.

Contributions to the privacy or security community (participation in bug bounty programs, public research, blogging, presentations, etc.) * Experience with big data and relational databases (Hive ...

New

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Compliance Operations Lead

New York, NY · On-site

$171K/yr

... test, or bug-bounty programs and translating findings into engineering action. * You write policy and you read code, and can sit with an auditor and a senior engineer in the same meeting and ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Designer

Augusta, GA · On-site

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Designer

Augusta, GA · On-site

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Projects include reforming digital services that provide military families access to critical benefits, running bug bounty programs to identify vulnerabilities and better secure defense systems ...

Showing results 21-40

Entry Level Bug Bounty Program information

See salary details

$16

$49

$78

How much do entry level bug bounty program jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for entry level bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is the difference between Entry Level Bug Bounty Program vs Entry Level Penetration Tester?

AspectEntry Level Bug Bounty ProgramEntry Level Penetration Tester
CredentialsBasic cybersecurity knowledge, certifications like CompTIA Security+Similar certifications, possibly more technical training
Work EnvironmentRemote, freelance, or platform-basedOften in-house or consulting firms, some remote options
Industry UsageWidely used in tech and cybersecurity sectorsCommon in security consulting and IT firms
Search & Comparison IntentFocus on crowdsourced vulnerability discoveryFocus on simulated or real-world security testing

While both roles involve cybersecurity skills, an Entry Level Bug Bounty Program typically involves participating in online platforms to find vulnerabilities remotely, often on a freelance basis. An Entry Level Penetration Tester conducts more structured security assessments, often within organizations or consulting firms. Both require foundational cybersecurity knowledge, but their work environments and approaches differ significantly.

How to get started with entry level bug bounty programs?

To start with entry level bug bounty programs, familiarize yourself with common web vulnerabilities such as SQL injection and cross-site scripting, and learn to use tools like Burp Suite and OWASP ZAP. Building a solid understanding of web security, practicing on platforms like HackerOne or Bugcrowd, and participating in online communities can help develop your skills and increase your chances of success.

How to start a career in entry level bug bounty program?

To start a career in an entry level bug bounty program, develop skills in web security, programming, and vulnerability assessment through online courses and practice platforms. Gain experience by participating in bug bounty programs on platforms like HackerOne or Bugcrowd, and familiarize yourself with common security tools and reporting processes. Building a strong understanding of security concepts and ethical hacking is essential for success in this field.
More about Entry Level Bug Bounty Program jobs

What cities are hiring for Entry Level Bug Bounty Program jobs?

Cities with the most Entry Level Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Entry Level Bug Bounty Program jobs?

States with the most job openings for Entry Level Bug Bounty Program jobs include:

Infographic showing various Entry Level Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 18% Part Time, and 4% Contract. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Full-time

PTO

Re-posted 26 days ago


Job description

TLDR: We're looking for an AI Red Team Engineer to break LLM-powered systems responsibly, automate the repetitive attacks, and turn their findings into clear evidence that powers customer demos, security reviews, and sales conversations. You'll own hands-on adversarial testing end to end: find the failure, prove it, script it, and write it up.
About us
White Circle is an AI Safety company building the safety, reliability, and optimization layer for AI systems. At the core of our platform are policies - simple natural-language rules that define what an AI model should and shouldn't do. We automatically test, enforce, and continuously improve these policies at scale.
  • We've raised $11M from top funds, founders, and senior leaders at OpenAI, Anthropic, HuggingFace, Mistral, DeepMind, Datadog, Sentry, and others
  • We process over one hundred million API calls every month
  • We fine-tune and train our own LLMs so they run faster and cheaper than any open or proprietary model

We're a small, highly focused team. If you want to work deeply on hard problems, see your work ship to production quickly, and influence how AI safety is actually built - you're the one we need.
You will:
  • Red-team LLM-powered systems: chatbots, copilots, RAG pipelines, AI agents, tool-calling workflows, and API-based AI products.
  • Test for jailbreaks, prompt injection, system-prompt and tool leakage, sensitive-data and context leakage, unsafe outputs, policy bypass, tool misuse, excessive agency, resource and token-cost abuse, and business-logic abuse.
  • Write lightweight Python to automate attacks, run prompt sets, call model APIs, collect and score responses, and generate repeatable reports.
  • Build and maintain an internal attack library: prompts, scenarios, test cases, regression tests, scoring rubrics, and reusable demo cases.
  • Turn model failures into clear reports: what happened, why it matters, how to reproduce it, how severe it is, and how to fix it.
  • Convert successful attacks into regression tests and product requirements.
  • Track new red-team and safety techniques and fold the useful ones into our tests.
  • Support GTM by producing strong, credible evidence for customer demos, security reviews, and sales conversations.

You'll fit right in if you:
  • Genuinely love breaking things and reasoning adversarially.
  • Have a background in QA automation, AppSec, API/security/pen testing, or bug bounty.
  • Have strong Python scripting skills.
  • Have experience testing APIs, web apps, backends, or SaaS products.
  • Are hands-on with LLMs, prompts, system instructions, RAG, agents, and tool/function calling.
  • Understand LLM-specific abuse vectors (prompt injection, jailbreaks, data leakage, tool misuse, excessive agency, token-cost exhaustion).
  • Can find bypasses, abuse edge cases, chain failures, and reason about real-world impact.
  • Can separate real customer risk from low-impact prompt tricks.
  • Write clear, reproducible bug reports in clear English.
  • Can move fast without perfect requirements.
  • Hold a firm ethical line: you red-team to make systems safer, operate within scope and the law, and don't produce or traffic in genuinely harmful material.

A big plus:
  • Experience with Burp Suite, Postman, Playwright, pytest.
  • Experience with modern LLM red-teaming automated agents and pipelines.
  • Familiarity with LangChain, LangGraph, LlamaIndex, RAG pipelines, AI agents, tool/function calling, and LLM-as-judge evaluation.
  • Familiarity with OWASP LLM Top 10, OWASP Web Top 10, MITRE ATLAS, or other AI security taxonomies.
  • Experience testing RAG systems, AI agents, tool-calling workflows, browser agents, or internal copilots.
  • Experience writing customer-facing security reports.
  • Experience with trust & safety, abuse prevention, fraud, moderation, or platform security.
  • Experience building eval pipelines, regression suites, dashboards, or CI-friendly security tests.
  • A track record in CTFs, red-team competitions, or responsible-disclosure / bounty programs.

Why White Circle
  • Paid time off in line with your local regulations, no matter where you work from
  • Meaningful equity package
  • All the hardware, tools, and services you need
  • Covered subscriptions for AI agents
  • Team off-sites twice a year: we've recently been to the Alps and to Saint-Tropez

How we hire
  1. Intro call with HR (25 min)
  2. Take-home test task
  3. Technical interview (60 min)
  4. Final call with CEO (45 min)

Please submit your application in English