1

Hourly Bug Bounty Program Jobs in Utah (NOW HIRING)

Product Security Engineer

Lehi, UT · On-site

$67.61 - $84.51/hr

You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a ...

Product Security Engineer

Lehi, UT · On-site

$67.61 - $84.51/hr

You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Hourly Bug Bounty Program information

Which bug bounty pays the most?

In bug bounty programs, payouts vary widely depending on the severity and impact of the vulnerability, with some programs offering rewards of hundreds of thousands of dollars for critical findings. Platforms like HackerOne and Bugcrowd host high-paying programs, especially for critical security flaws in major companies. Successful bug bounty hunters often have strong technical skills, knowledge of web security, and experience with bug tracking tools.

What are some common challenges faced by participants in an hourly bug bounty program, and how can they overcome them?

Participants in an hourly bug bounty program often face challenges such as quickly identifying valid vulnerabilities, managing time efficiently, and competing with other security researchers for rewards. Staying organized and maintaining up-to-date knowledge of common vulnerabilities and testing techniques are essential. Collaborating with the program's security team for clarification and feedback can also help improve your effectiveness and increase your chances of success.

How much money can you make doing bug bounties?

The earnings from bug bounty programs vary widely; top security researchers can make thousands to hundreds of thousands of dollars annually by finding critical vulnerabilities. Income depends on the scope of programs, the severity of bugs found, and the researcher’s skills and experience. Consistent success often requires knowledge of security testing tools and programming languages.

What is an Hourly Bug Bounty Program?

An Hourly Bug Bounty Program is a cybersecurity initiative where organizations pay security researchers or ethical hackers by the hour to identify and report vulnerabilities in their systems. Unlike traditional bug bounty programs that reward based on the severity of discovered bugs, this model compensates participants for their time and effort, even if they do not find any vulnerabilities. This structure can attract a broader range of skilled testers and provide continuous security assessment. It also allows organizations to receive more comprehensive feedback on their security posture.

What companies pay bug bounties?

Many technology companies, including Google, Microsoft, Facebook, Apple, and Uber, run bug bounty programs that pay security researchers for discovering and responsibly reporting vulnerabilities. These programs are often hosted on platforms like HackerOne and Bugcrown, and they typically offer rewards based on the severity of the findings and the quality of reports.

How much does Amazon pay for bug bounty?

Amazon's bug bounty program offers rewards that can range from a few hundred to over $100,000 depending on the severity and impact of the vulnerability. Bug bounty hunters typically need skills in security testing, and payouts are based on the quality and significance of the reported issues.

What are the key skills and qualifications needed to thrive as an Hourly Bug Bounty Program participant, and why are they important?

To excel in an Hourly Bug Bounty Program, you need deep knowledge of cybersecurity principles, vulnerability assessment, and web application security, often demonstrated by experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Metasploit, and various bug tracking or reporting platforms is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify, document, and report vulnerabilities clearly. These competencies are crucial for protecting client systems, ensuring precise reporting, and maximizing your success and reputation within the bug bounty community.
What are the most commonly searched types of Bug Bounty Program jobs in Utah? The most popular types of Bug Bounty Program jobs in Utah are:
What job categories do people searching Hourly Bug Bounty Program jobs in Utah look for? The top searched job categories for Hourly Bug Bounty Program jobs in Utah are:
What cities in Utah are hiring for Hourly Bug Bounty Program jobs? Cities in Utah with the most Hourly Bug Bounty Program job openings:

Product Security Engineer

NextDeavor Inc.

Lehi, UT • On-site

$67.61 - $84.51/hr

Contractor

Medical, Dental, Vision, Retirement

Posted 25 days ago


Job description

Product Security Engineer
Full-time
Lehi, UT

You’ll be joining Adobe on a contract opportunity, employed through NextDeavor

Benefits You'll Love

NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave eligibility is contingent on state of residence Optional 401k Plan (excludes employer match) Opportunity to get your foot in the door at a well-established corporation, with potential for extended or permanent full-time employment

Become a Key Player as a Product Security Engineer

You will lead triage and validation of external vulnerability reports for the client's products, ensuring timely, accurate resolution and clear researcher communications. You will work closely with internal engineering and security stakeholders to drive remediation and improve the bug bounty program's effectiveness. This is a contract engagement expected to backfill a team member on leave.

Here's How You'll Make an Impact on the Team
  • Triage incoming vulnerability reports from the bug bounty platform, assess validity, impact, and scope.
  • Assign CVSS scores and severity ratings following internal guidelines and industry standards.
  • Reproduce proof-of-concept exploits across web, API, and mobile surfaces to validate reports.
  • Communicate with external researchers to request clarifications, provide status updates, and manage expectations.
  • Coordinate confirmed vulnerabilities with product engineering teams for remediation.
  • Identify duplicates, out-of-scope, or informational reports and close them with clear explanations.
  • Contribute to internal documentation, triage runbooks, and severity calibration guidelines.
  • Flag systemic or critical findings to the Bug Bounty team for escalation.
Here's What You'll Need to Be Successful in This Role
  • 3+ years of experience in application security, penetration testing, or a bug bounty/vulnerability disclosure role.
  • Strong understanding of CVSS v3.1 and hands-on experience applying it to real-world vulnerabilities.
  • Proficiency with common web vulnerability classes: XSS, SQL injection, SSRF, IDOR, authentication flaws, and business logic issues.
  • Ability to reproduce and validate PoC exploits using tools such as Burp Suite, browser DevTools, curl, and custom scripts.
  • Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and responsible disclosure processes.
  • Solid written communication skills for clear, constructive responses to external researchers.
  • Familiarity with attacker techniques against LLM systems and generative AI products.
  • Knowledge of OWASP Top 10 vulnerabilities and mitigation techniques.
Here's What Else Might Help You Out
  • Experience with cloud environments (AWS, Azure, GCP) and API security testing.
  • Hands-on penetration testing experience for AI/ML and LLM-powered products, including chat interfaces and inference APIs.
  • Prior participation in bug bounty programs as a researcher.
  • Familiarity with CWE taxonomy and CVE assignment processes.
  • Background working within a large enterprise or SaaS security organization.
Pay Range

$67.61 - $84.51/hour

Ready to Make Your Mark?

This role may fill quickly. Submit your resume to be considered.

Apply with Pioneers here