1

Flexible Bug Bounty Jobs (NOW HIRING)

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the ... flexible work hours and arrangements are part of our culture When we feel supported in the ...

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the ... flexible work hours and arrangements are part of our culture When we feel supported in the ...

Technical Program Manager, Bug Bounty

Seattle, WA · On-site

$146K - $190K/yr

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the ... flexible work hours and arrangements are part of our culture. When we feel supported in the ...

... our bug bounty program • Security Architecture Review: Collaborate with development teams to ... flexible and constructive approach when solving problems. • You are able to make trade-offs ...

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Defending production infrastructure Being flexible, communicating clearly, and establishing and ...

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Defending production infrastructure Being flexible, communicating clearly, and establishing and ...

Validate, triage, and coordinate security findings from bug bounty, third-party pentests, and cloud ... Flexible PTO * ClassPass membership * Monthly commuter benefit * Team building events & happy hours

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Defending production infrastructure Being flexible, communicating clearly, and establishing and ...

Product Security Engineer

Seattle, WA · On-site

$188K - $250K/yr

This flexible approach gives team members the best of both worlds: plenty of focus time along with ... Help drive improvements across our Product Security tooling, automation, and bug bounty program.

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ... Perks * Flexible work environment - ClickHouse is a globally distributed company and remote ...

Marketing Lead

San Carlos, CA · On-site

$120 - $160/hr

Own the go‑to‑market strategy for core products, including Managed Triage and Bug Bounty ... Benefits * 100% remote‑first work environment with flexible schedule. * Autonomous work ...

Active involvement in cybersecurity communities, research, or bug bounty programs * Certifications ... Flexible work hours with hybrid remote options * Opportunity to work with international ...

You have a track record as a bug bounty veteran. * Cryptography. Attacks, protocol design, and ... Flexible hours, remote work, and both full-time and part-time opportunities. We have a NYC office ...

Driving and supporting bug bounty program, application security reviews and threat modeling ... You employ a flexible and constructive approach when solving problems * You are able to make trade ...

next page

Showing results 1-20

Flexible Bug Bounty information

See salary details

$7

$13

$31

How much do flexible bug bounty jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for flexible bug bounty in the United States is $13.77, according to ZipRecruiter salary data. Most workers in this role earn between $10.58 and $14.42 per hour, depending on experience, location, and employer.

What is a flexible bug bounty?

A flexible bug bounty is a program offered by organizations that allows security researchers to find and report vulnerabilities in their systems, with flexible terms regarding scope, payouts, and participation. Unlike traditional bug bounties with strict rules, flexible programs adapt to the needs of the company and the researchers, often allowing for negotiation on rewards and eligible targets. This approach encourages a wider range of security experts to participate and helps organizations address security issues more dynamically.

What are the key skills and qualifications needed to thrive as a bug bounty hunter?

To thrive as a Bug Bounty Hunter, you need a deep understanding of cybersecurity principles, web application vulnerabilities, and ethical hacking, often supported by experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various scripting languages is crucial for identifying and exploiting security flaws. Critical thinking, persistence, and clear communication are vital soft skills for analyzing systems and reporting findings effectively. These skills are important because they enable hunters to identify security risks, provide actionable insights, and contribute to safer digital environments.

What is the difference between Flexible Bug Bounty vs Penetration Tester?

AspectFlexible Bug BountyPenetration Tester
CredentialsTypically no formal certifications required, but knowledge of security best practices is essentialOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentRemote, project-based, often freelance or platform-drivenUsually employed by security firms or organizations, with on-site or remote work
Industry UsageCommon in cybersecurity communities, freelance platforms, and bug bounty programsUsed by security consulting firms, corporate security teams, and government agencies

Flexible Bug Bounty programs allow security researchers to find vulnerabilities on various platforms remotely and on a freelance basis. Penetration testers are professional security experts hired to assess systems, often with formal certifications and a more structured approach. Both roles focus on identifying security flaws but differ in work setup and credentials.

What are some common challenges faced by professionals working in flexible bug bounty roles?

Professionals in flexible bug bounty roles often encounter challenges such as rapidly changing vulnerability landscapes, the need to stay updated with the latest security research, and managing inconsistent workflows due to the on-demand nature of assignments. Because bug bounty work is typically independent and remote, clear communication with program managers and other security researchers is essential for success. Additionally, effectively prioritizing time and tasks, especially when juggling multiple programs or platforms, is crucial for maximizing both learning and earning potential.
More about Flexible Bug Bounty jobs
What cities are hiring for Flexible Bug Bounty jobs? Cities with the most Flexible Bug Bounty job openings:
What are the most commonly searched types of Bug Bounty jobs? The most popular types of Bug Bounty jobs are:
What states have the most Flexible Bug Bounty jobs? States with the most job openings for Flexible Bug Bounty jobs include:
Infographic showing various Flexible Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 66% Full Time, 30% Part Time, and 3% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $28,637 per year, or $13.8 per hour.

Technical Program Manager, Bug Bounty

Amazon

Seattle, WA

$146K - $190K/yr

Full-time

Re-posted 21 days ago


Amazon rating

7.4

Company rating: 7.4 out of 10

Based on 7,082 frontline employees who took The Breakroom Quiz

6th of 39 rated national retailers


Job description

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex, cross-functional programs that improve how we identify, triage, and resolve externally reported security vulnerabilities. You'll work across engineering, security, and business teams to improve processes, remove roadblocks, and ensure researchers have the access and support they need to help raise our security bar.
You'll partner with internal teams to close vulnerabilities quickly and effectively, and you'll help shape the future of how Amazon engages with the global security research community

This is a fast-paced, high-impact role that requires strong ownership, sound judgment, and the ability to dive deep into technical problems while keeping stakeholders aligned.
Key job responsibilities
- Lead technical programs that improve how Amazon responds to externally reported vulnerabilities
- Define and scale internal processes for vulnerability intake, triage, and resolution
- Build durable solutions that reduce repeat issues through automation, better tooling, and improved service team accountability
- Collaborate with partner teams to improve test account support and ensure researchers have the access they need to test securely and effectively
- Communicate clearly and regularly with senior leaders, engineering teams, and external researchers
- Own the long-term roadmap for specific areas of the Bug Bounty program and influence the broader team strategy
A day in the life
You will spend most days working with engineers, builder teams, and partner teams to improve how we handle bug bounty findings. You might be mapping out a plan to improve processes, coordinating across teams to roll out new tools, or identifying where we need better support for internal owners. Some days will focus on clearing blockers and aligning stakeholders

Others will focus on building the right systems to scale the program as Amazon grows.
About the team
The Bug Bounty team helps protect Amazon and its customers by working with external security researchers who report vulnerabilities in our public-facing services. We partner with security engineers and builder teams across the company to investigate findings, improve our response processes, and build systems that scale. Our mission is to raise the security bar across Amazon by learning from every bug

We value clear thinking, sound judgment, and strong ownership, and we work every day to make Amazon more secure for customers around the world.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences

Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness

Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture

When we feel supported in the workplace and at home, there's nothing we can't achieve.


What Amazon employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Amazon logo

About Amazon

Sourced by ZipRecruiter

Amazon.com, Inc., commonly known as Amazon, is an American multinational technology company. It was founded by Jeff Bezos in 1994 and initially started as an online marketplace for books. Since then, Amazon has expanded its operations and become one of the largest e-commerce companies in the world. Amazon's primary business is its online retail platform, where customers can purchase a vast array of products, including electronics, clothing, books, home goods, and much more. The company offers a convenient and user-friendly shopping experience, with features such as fast shipping, customer reviews, and personalized recommendations. In addition to its e-commerce platform, Amazon has diversified its business into various other areas. One of its notable ventures is Amazon Web Services (AWS), a comprehensive cloud computing platform that provides services such as storage, compute power, and database management to individuals and businesses. AWS has become a leader in the cloud computing industry, powering many websites and applications worldwide. Amazon has also developed its own consumer electronics, including the popular Amazon Kindle e-reader, Fire tablets, Fire TV streaming devices, and the Alexa-powered Echo smart speakers. The Alexa voice assistant, integrated into these devices, allows users to interact with their devices using voice commands, perform tasks, and access information. Furthermore, Amazon has expanded into media and entertainment. It operates Prime Video, a streaming service that offers a wide range of movies, TV shows, and original content. Amazon Music provides a platform for streaming and purchasing digital music, while Audible offers audiobooks and other audio content. The company's commitment to customer satisfaction and convenience is demonstrated by its membership program, Amazon Prime. Prime members receive various benefits, including free two-day shipping, access to streaming services, exclusive deals, and more.

Industry

It services, book publishers, retail, real estate and computer and electronic product manufacturing

Company size

10,000+ Employees

Headquarters location

Seattle, WA, US