1

Flexible Bug Bounty Jobs (NOW HIRING)

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Defending production infrastructure Being flexible, communicating clearly, and establishing and ...

Sr. Application Security Engineer

Redmond, WA ยท On-site

$170K - $235K/yr

You will also be responsible for monitoring and responding to bug bounty submissions. Ideally, you ... Defending production infrastructure Being flexible, communicating clearly, and establishing and ...

Showing results 21-40

Flexible Bug Bounty information

See salary details

$7

$13

$31

How much do flexible bug bounty jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for flexible bug bounty in the United States is $13.77, according to ZipRecruiter salary data. Most workers in this role earn between $10.58 and $14.42 per hour, depending on experience, location, and employer.

What is a flexible bug bounty?

A flexible bug bounty is a program offered by organizations that allows security researchers to find and report vulnerabilities in their systems, with flexible terms regarding scope, payouts, and participation. Unlike traditional bug bounties with strict rules, flexible programs adapt to the needs of the company and the researchers, often allowing for negotiation on rewards and eligible targets. This approach encourages a wider range of security experts to participate and helps organizations address security issues more dynamically.

What are the key skills and qualifications needed to thrive as a bug bounty hunter?

To thrive as a Bug Bounty Hunter, you need a deep understanding of cybersecurity principles, web application vulnerabilities, and ethical hacking, often supported by experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various scripting languages is crucial for identifying and exploiting security flaws. Critical thinking, persistence, and clear communication are vital soft skills for analyzing systems and reporting findings effectively. These skills are important because they enable hunters to identify security risks, provide actionable insights, and contribute to safer digital environments.

What are some common challenges faced by professionals working in flexible bug bounty roles?

Professionals in flexible bug bounty roles often encounter challenges such as rapidly changing vulnerability landscapes, the need to stay updated with the latest security research, and managing inconsistent workflows due to the on-demand nature of assignments. Because bug bounty work is typically independent and remote, clear communication with program managers and other security researchers is essential for success. Additionally, effectively prioritizing time and tasks, especially when juggling multiple programs or platforms, is crucial for maximizing both learning and earning potential.

What is the difference between Flexible Bug Bounty vs Penetration Tester?

AspectFlexible Bug BountyPenetration Tester
CredentialsTypically no formal certifications required, but knowledge of security best practices is essentialOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentRemote, project-based, often freelance or platform-drivenUsually employed by security firms or organizations, with on-site or remote work
Industry UsageCommon in cybersecurity communities, freelance platforms, and bug bounty programsUsed by security consulting firms, corporate security teams, and government agencies

Flexible Bug Bounty programs allow security researchers to find vulnerabilities on various platforms remotely and on a freelance basis. Penetration testers are professional security experts hired to assess systems, often with formal certifications and a more structured approach. Both roles focus on identifying security flaws but differ in work setup and credentials.

How much do bug bounty programs pay?

Bug bounty programs pay security researchers based on the severity and impact of the vulnerabilities they discover, with rewards ranging from $100 to over $100,000 per bug. Payments depend on the program, the complexity of the issue, and the organization's budget, with some programs offering higher rewards for critical findings. Successful bug hunters often use tools like bug tracking platforms and need strong technical skills to maximize their earnings.
More about Flexible Bug Bounty jobs

What cities are hiring for Flexible Bug Bounty jobs?

Cities with the most Flexible Bug Bounty job openings:

What are the most commonly searched types of Bug Bounty jobs?

The most popular types of Bug Bounty jobs are:

What states have the most Flexible Bug Bounty jobs?

States with the most job openings for Flexible Bug Bounty jobs include:

Infographic showing various Flexible Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 67% Full Time, 29% Part Time, and 3% Contract. Highlights an 88% Physical, 1% Hybrid, and 11% Remote job distribution, with an average salary of $28,637 per year, or $13.8 per hour.

Penetration Tester, Frontier AI Evaluation

Cobalt

Hayward, CA โ€ข On-site

Other

Posted 2 days ago

New


Job description

About the role:

Cobalt is seeking experienced penetration testers to contribute expert reasoning, technical problems, and evaluation data used to train and assess frontier AI models on security tasks.

This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, vulnerability researchers, exploit developers, application security engineers, and serious bug bounty hunters, whether from consultancies, internal security teams, or independent practice.

You do not need prior experience in data annotation or AI research. What matters is that you can find and reason about real weaknesses in software and infrastructure unaided, and that you can document how you got there clearly enough for another practitioner to follow.

All work is performed against sandboxed environments and purpose-built targets supplied by us or by the lab. We do not accept work performed against systems you are not authorized to test, and we do not accept material obtained without authorization or covered by a client agreement.


What you'll do:

Depending on the project, you may:

  • Produce written testing traces on security tasks, capturing how you form and test hypotheses, what you rule out and why, and how you arrive at a working approach, rather than only the end result
  • Author novel security problems, capture-the-flag style challenges, and lab environments with verifiable success criteria
  • Evaluate model-generated security content and code, ranking responses, explaining what makes the stronger one stronger, and identifying the specific step at which the technical reasoning breaks down
  • Assess whether stated findings are supported by the underlying evidence, and identify inconsistencies between reported results and what the target actually does
  • Design rubrics and partial-credit criteria for scoring multistep testing and remediation tasks

Projects follow their own guidelines, scope rules, and quality standards, and you will work with feedback from reviewers and lab research teams.


Required qualification:

  • Demonstrable penetration testing experience, evidenced by professional engagements, published vulnerability research or CVEs, a substantive bug bounty record, competitive CTF results, or comparable work
  • Strong hands-on coding ability in at least one of Python, C, C++, Go, Rust, or JavaScript, sufficient to read unfamiliar codebases and write your own tooling rather than only running existing tools
  • Depth in at least one area, for example web and API security, cloud and container security, network and infrastructure testing, mobile security, or binary exploitation and reverse engineering
  • Ability to explain each step of your reasoning clearly in writing, and to produce documentation another practitioner could reproduce
  • Willingness to work strictly within defined scope and authorization, and to sign a confidentiality agreement covering project materials

Certifications such as OSCP, OSWE, OSEP, GPEN, or GXPN are useful but not required.


Why join Cobalt AI:

  • Advance frontier AI where it counts. Apply your testing expertise to data that frontier labs cannot obtain any other way, where your judgment directly shapes how the next generation of models reasons about security.
  • Grow professionally. Expand your influence through evaluation projects, advisory roles, and research collaborations, while developing a working understanding of how frontier models are trained and assessed.
  • Work with a top-tier network. Collaborate with security practitioners and researchers from leading organizations on high-impact, flexible work.
  • Set your own schedule. Flexible 10 to 40 hour weeks that fit around your existing engagements and your life.
  • Competitive pay. Rates vary by project and are determined by a number of factors, including scope, skillset, and experience.