1

Freelance Bug Bounty Program Jobs (NOW HIRING)

$140 - $230/hr

You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...

New

Security Engineer, Application Security

New York, NY · On-site

$130K - $400K/yr

  • Medical

  • Dental

  • Vision

Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure What We're Looking For * You've found and fixed real vulnerabilities in production ...

Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Engineering Manager, Proactive Security

Los Angeles, CA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Partner cross-functionally with Product Engineering, Legal, Security Engineering Platform, Data teams and XFN partners to execute rigorous, agent enabled cross-brand Bug Bounty Program, Penetration ...

Red Team Engineer/ Offensive Security Lead

$104K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program. If you've spent years thinking like an adversary and you ...

Cybersecurity Engineer (Remote)

Lehi, UT · On-site +1

  • Retirement

  • PTO

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Senior Product Security Engineer

$117K - $160K/yr

Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security Automation : Develop and implement ...

Senior Security Engineer

$117K - $160K/yr

Preferred : • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and ISO 42001 • Hands-on experience in offensive security (eg, through bug bounty programs or CTFs) Company : Zip is ...

Showing results 21-40

Freelance Bug Bounty Program information

See salary details

$9

$22

$68

How much do freelance bug bounty program jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for freelance bug bounty program in the United States is $22.97, according to ZipRecruiter salary data. Most workers in this role earn between $18.75 and $18.75 per hour, depending on experience, location, and employer.

What is a freelance bug bounty program?

Freelance bug bounty programs are initiatives run by companies or platforms that invite independent security researchers—often called ethical hackers—to identify and report vulnerabilities in their software or systems. Participants work on a freelance basis, choosing which programs to join and which vulnerabilities to hunt for, and are typically rewarded with monetary payouts or recognition for valid findings. This model helps organizations discover and fix security issues before they can be exploited maliciously, while providing freelancers with income and experience in cybersecurity. Anyone with the necessary skills can participate, making it a flexible career or side job for security enthusiasts.

What are the key skills and qualifications needed to thrive as a freelance bug bounty hunter?

To thrive as a Freelance Bug Bounty Hunter, you need a solid understanding of web application security, programming/scripting languages, and vulnerability assessment methodologies—often demonstrated by hands-on experience or certifications like OSCP. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential for effective testing and reporting. Standout soft skills include analytical thinking, persistence, attention to detail, and clear written communication for submitting thorough vulnerability reports. These skills are crucial for identifying and responsibly disclosing security flaws, earning rewards, and building a strong reputation in the cybersecurity community.

What are some common challenges faced by freelancers participating in bug bounty programs, and how can they be overcome?

Freelancers in bug bounty programs often face challenges such as intense competition from other researchers, staying updated with the latest security vulnerabilities, and navigating varying program rules. To overcome these, it's important to continually hone your technical skills, engage with the security community for knowledge sharing, and thoroughly review each program's scope and guidelines before submitting reports. Building a reputation for high-quality, well-documented submissions can also help you stand out and secure more consistent rewards.

What is the difference between Freelance Bug Bounty Program vs Freelance Penetration Tester?

AspectFreelance Bug Bounty ProgramFreelance Penetration Tester
CredentialsKnowledge of security testing, bug reportingCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, online platformsRemote or on-site, client-specific engagements
Industry UsageTech companies, cybersecurity platformsConsulting firms, corporate security teams
Search & Comparison IntentFocus on bug bounty programs, online testingFocus on security assessments, penetration testing

While both roles involve security testing, Freelance Bug Bounty Programs primarily focus on identifying vulnerabilities through online platforms and reporting bugs, often without formal certifications. Freelance Penetration Testers conduct comprehensive security assessments, often requiring certifications and on-site work. The choice depends on your skills, certifications, and preferred work environment.

How much do freelance bug bounty program hunters make?

Freelance bug bounty hunters can earn from a few hundred to several thousand dollars per vulnerability, with top performers sometimes making over $100,000 annually. Earnings depend on the severity of the bugs found, the scope of the program, and the hunter's skills in security testing and tools like Burp Suite or Burp Suite, as well as their experience and reputation in the community.
More about Freelance Bug Bounty Program jobs

What cities are hiring for Freelance Bug Bounty Program jobs?

Cities with the most Freelance Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Freelance Bug Bounty Program jobs?

States with the most job openings for Freelance Bug Bounty Program jobs include:

Infographic showing various Freelance Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 1% Temporary, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $47,772 per year, or $23 per hour.

Senior Security Engineer - Product Security -- Ondo Finance

The Bitcoin Street Journal

On-site

$140 - $230/hr

Other

Posted yesterday

New


Job description

Apply Now ↗ You will be redirected to the employer's application page.

  • Location: United States
  • Sector: Blockchain
  • Source: web3.career
About Ondo

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems, which means our product surface has to hold up against both the ordinary threats that hit any high-value fintech and the specific ones that follow value on-chain.

About the Role

We are hiring a Senior Security Engineer – Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes.

This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security function like AppSec, Infrasec, and SecOps.

What You’ll Do
  • Drive threat modeling for new features, integrations, and architectural changes across the product surface. Push threat models past templates into decisions that engineering teams actually implement.
  • Own secure code review for high-risk changes — authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.
  • Expand the AppSec tooling stack and treat “reducing false positives” as a first-class deliverable. AI-native integrations are welcome.
  • Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls.
  • Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering.
  • Support and own appropriate scope for the intake and closure of findings from external audits and pentests — coordinate with audit vendors (Coinspect, Cantina, NCC Group, and others), organize findings into our internal risk register, and drive remediation with engineering owners.
  • Partner with engineering leads to align o secure-by-default patterns – libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant.
  • Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems in partnership with engineers who own the on-chain code.
  • Contribute to hiring, mentoring, and pushing the technical bar on the Security team.
What We’re Looking For
  • 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.
  • Strong threat modeling skills, appropriate to experience – you can drive a real threat model with an engineering team, not just fill in a template. In practice, we look for core understanding of industry-relevant TTPs and IoCs and strong intuitions on how to apply those lessons learned to our products.
  • Practical experience owning or majorly contributing to an AppSec tooling program. You have shipped rules, tuned noise, and measured impact.
  • Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming properly resourced to do so.
  • Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration well enough to reason about how a product vulnerability crosses into an infra risk.
  • Strong engineering partnership skills – you engage constructively, understand the “why” before proposing risk controls, you know when to accept risk, and you write things down.
  • Willing to grow into blockchain-adjacent product security on the job, including the specific attack surface introduced by wallet, signing, and on-chain-integration code.
Blockchain Exposure Note
  • This role firmly lives in Web2 prodsec. But, it also requires someone who understands what “Web2 vs Web3” terminology means. In other words, how our products interact with blockchains creates unique threat models that all product security teammates must grasp. At a minimum, by Day 1 you should have strong intuitions about how blockchains will make your prodsec experience unique, you should grasp the common terminologies, and you should be able to discuss with colleagues several incident post-mortems that demonstrate how Web2 compromises lead to Web3 funds losses.
  • You do not need to be an expert in smart contract auditing, blockchain security architectures, or decentralized consensus-driven risk controls.
Nice to Have
  • Prior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.
  • Familiarity with wallet, signing, or key-management flows.
  • Reading-level familiarity with Solidity or Rust, target: when ProdSec intersects with smart contracts or other on-chain applications, you can parse what the code is likely doing, and work with blockchain security subject matter experts from there.
  • Bug bounty history – reports, CVEs, or published write-ups.
  • Public output – talks, blog posts, open-source tools, CVEs.
How We Work

The Security team values a high trust team environment where respectful candor can thrive. We expect senior engineers to have an opinionated take on how to accomplish a task, accept feedback from the team and other external stakeholders and return it in kind, and to always assume positive intent. Professionalism, ethics, and enabling stakeholders towards common goals are important always.

When applying, mention the word CANDYSHOP to show you read the job post completely.

#J-18808-Ljbffr