1

Home Based Bug Bounty Jobs (NOW HIRING)

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named ... Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination ...

About the Role: We're looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty ...

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions ... Environment - remote, work-from-home 100% of the time. Pay Range Disclosure At Bugcrowd, we strive ...

Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures ... You understand how different test types (vulnerability scanning, penetration testing, bug bounty ...

$81 - $128/hr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty ... A USD$500 Home office setup if you're a remote employee. * Global Gatherings - We believe in the ...

New

Shape Persona's presence in the security research community -- running the bug bounty program that ... Based in SF Relocation assistance available. Full-time Employee Benefits and Perks For full-time ...

$180 - $250/hr

... bug bounty programs. * Partner with DevOps and engineering teams to automate security controls ... Fully integrate security into CI/CD across major engineering organizations and implement risk-based ...

... bug bounty programs. * Partner with DevOps and engineering teams to automate security controls ... Fully integrate security into CI/CD across major engineering organizations and implement risk-based ...

We're based in San Francisco and backed by leading investors including Altos Ventures, BoxGroup ... Track record in bug bounty, CTF, or model red teaming competitions. * Experience building automated ...

New

Validate, triage, and coordinate security findings from bug bounty, third-party pentests, and cloud ... The salary for this position is determined based on a variety of job-related factors that may ...

Validate, triage, and coordinate security findings from bug bounty, third-party pentests, and cloud ... The salary for this position is determined based on a variety of job-related factors that may ...

... based on testing results, risk severity, and the Company's AI risk appetite. External Partnerships & Coordination * Coordinate with external consultants, specialized AI security firms, and bug bounty ...

Showing results 21-40

Home Based Bug Bounty information

See salary details

$9

$20

$27

How much do home based bug bounty jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for home based bug bounty in the United States is $20.88, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $22.60 per hour, depending on experience, location, and employer.

What is a home based bug bounty?

Home based bug bounty jobs involve working remotely to find and report security vulnerabilities in software, websites, or applications. These positions allow individuals to participate in bug bounty programs offered by companies, earning rewards or payments for successfully identifying and reporting bugs. Home based bug bounty hunters typically use their cybersecurity skills to test systems, submit detailed reports, and collaborate with organizations to improve their security. This flexible work arrangement is ideal for those interested in cybersecurity, ethical hacking, and remote work opportunities.

What are the key skills and qualifications needed to thrive as a home based bug bounty hunter?

To thrive as a Home Based Bug Bounty Hunter, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, ethical hacking, and often a background in computer science or related certifications like OSCP or CEH. Proficiency with tools such as Burp Suite, Metasploit, Nmap, and familiarity with bug bounty platforms like HackerOne or Bugcrowd is essential. Strong analytical thinking, problem-solving abilities, persistence, and effective written communication are valuable soft skills in this role. These skills and qualities are crucial for accurately identifying vulnerabilities, reporting them clearly, and maximizing success in competitive bug bounty programs.

What are some common challenges faced by home based bug bounty hunters, and how can they be addressed?

Home-based bug bounty hunters often face challenges such as staying updated with the latest security vulnerabilities, maintaining motivation without a traditional team environment, and managing time effectively across multiple programs. To address these, it's helpful to participate in online security communities, set regular work hours, and leverage collaboration tools for connecting with other researchers. Continuous learning and self-discipline are key to success, along with establishing a comfortable and distraction-free workspace.

What is the difference between Home Based Bug Bounty vs Remote Penetration Tester?

AspectHome Based Bug BountyRemote Penetration Tester
CredentialsKnowledge of cybersecurity, bug bounty platformsCertifications like OSCP, CEH often preferred
Work EnvironmentSelf-directed, flexible, home-basedRemote or on-site, client-specific environments
Industry UsageFreelance, independent security researchersConsultants, security firms, corporate security teams
Search/Comparison IntentFinding freelance bug bounty opportunitiesSeeking professional penetration testing services

Home Based Bug Bounty roles involve independent security researchers finding vulnerabilities via bug bounty platforms, often working from home with flexible hours. Remote Penetration Testers are professional security consultants hired by organizations to assess security remotely or on-site. While both require cybersecurity knowledge, bug bounty hunters focus on individual contributions, whereas penetration testers work within client projects with formal contracts.

Can you make a living doing home based bug bounties?

Home-based bug bounty programs allow security researchers to earn money by identifying vulnerabilities in software and websites. While some individuals earn a full-time income, success depends on skill level, experience, and the scope of programs they participate in; consistent earnings often require ongoing learning and reputation building. Many bug bounty hunters supplement their income with other cybersecurity activities or certifications.

What cities are hiring for Home Based Bug Bounty jobs?

Cities with the most Home Based Bug Bounty job openings:

What are the most commonly searched types of Bug Bounty jobs?

The most popular types of Bug Bounty jobs are:

What states have the most Home Based Bug Bounty jobs?

States with the most job openings for Home Based Bug Bounty jobs include:

What job categories do people searching Home Based Bug Bounty jobs look for?

The top searched job categories for Home Based Bug Bounty jobs are:

Infographic showing various Home Based Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 16% Part Time, and 6% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $43,422 per year, or $20.9 per hour.

Senior Product Security Engineer

Webhosting

Austin, TX • On-site

$180 - $240/hr

Other

Posted 17 days ago


Key responsibilities

  • Lead security assessments and vulnerability operations for Cloudflare's core software products.

  • Analyze system architecture, conduct threat modeling, and ensure security findings are triaged, routed, and mitigated within SLAs.

  • Build and deploy AI-driven solutions to automate code analysis, optimize triage, and scale product security workflows.


Job description

Available Locations:

Austin, TX

About the role

As a Senior Product Security Engineer, you will lead security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.

On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Responsibilities
  • Autonomously Drive AI Security Innovation:Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling:Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management:Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership:Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support:Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship:Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.
Desirable Skills, Knowledge, and Experience:
  • Senior-Level Product/AppSec Expertise:Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering:Demonstrated ability to build production-grade automation scripts and tools . Must possess hands‑on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis:Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership:Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication:Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.
  • Offensive Mastery:Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Program Management Experience:Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases
Equity

This role is eligible to participate in Cloudflare’s equity plan.

Project Galileo : Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use – it is the first consumer-focused service Cloudflare has ever released. Here’s the deal – we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

#J-18808-Ljbffr