1

On Call Bug Bounty Program Jobs (NOW HIRING)

Senior Security Engineer - Product Security

$117K - $160K/yr

You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...

$140 - $230/hr

You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...

New

Senior Product Security Engineer

$117K - $160K/yr

Contribute to our vulnerability management program, including triaging bug bounty and vulnerability ... Strong incident response skills and experience participating in on-call rotations. * Excellent ...

Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Red Team Engineer/ Offensive Security Lead

$104K - $138K/yr

You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program. If you've spent years thinking like an adversary and you ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Senior Security Engineer

$117K - $160K/yr

Preferred : • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and ISO 42001 • Hands-on experience in offensive security (eg, through bug bounty programs or CTFs) Company : Zip is ...

Showing results 21-40

On Call Bug Bounty Program information

See salary details

$16

$49

$78

How much do on call bug bounty program jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for on call bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is an On Call Bug Bounty Program?

An On Call Bug Bounty Program is a security initiative where organizations invite ethical hackers to find and report vulnerabilities in their systems on an as-needed or on-call basis. Unlike traditional bug bounty programs, this model may involve a select group of trusted researchers who are contacted to test specific features or during particular timeframes. It helps organizations quickly identify and address critical security risks, often before public launch or after significant updates. Participants receive rewards or recognition for valid vulnerability submissions, supporting a proactive approach to cybersecurity.

What are the main challenges faced by professionals working in an On Call Bug Bounty Program role?

Professionals in On Call Bug Bounty Program roles often encounter challenges such as managing unpredictable workloads, rapidly assessing and triaging incoming vulnerability reports, and maintaining effective communication with both internal security teams and external researchers. The on-call aspect can require quick decision-making and adaptability, especially when critical issues arise outside of regular hours. Additionally, staying updated on the latest security threats and vulnerabilities is essential to effectively prioritize and address reported bugs.

What are the key skills and qualifications needed to thrive as an On Call Bug Bounty Program participant?

To thrive in an On Call Bug Bounty Program, you need strong knowledge of cybersecurity principles, vulnerability assessment, and hands-on experience in penetration testing, typically demonstrated through relevant certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and bug tracking platforms is essential for efficiently identifying and reporting security flaws. Attention to detail, persistence, and strong written communication skills help you document findings and collaborate with program stakeholders. These competencies are vital to ensure vulnerabilities are accurately detected and responsibly disclosed to protect organizational assets.

What is the difference between On Call Bug Bounty Program vs Penetration Tester?

AspectOn Call Bug Bounty ProgramPenetration Tester
CredentialsNone required; often self-taught or certified in security basicsCertifications like OSCP, CEH, or CISSP typically required
Work EnvironmentRemote, flexible, project-basedOften on-site or hybrid, structured engagements
Employer & Industry UsageCompanies seeking external security testing via crowdsourcingSecurity firms or internal teams conducting authorized testing
Search & Comparison IntentUnderstanding freelance or crowdsourced security testing optionsProfessional security assessment roles

The On Call Bug Bounty Program involves independent security researchers testing applications remotely on a project basis, often without formal employment. Penetration Testers are typically employed or contracted professionals with certifications, performing structured security assessments. Both roles focus on identifying vulnerabilities but differ in credentials, work environment, and engagement style.

More about On Call Bug Bounty Program jobs

What cities are hiring for On Call Bug Bounty Program jobs?

Cities with the most On Call Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

Infographic showing various On Call Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 1% Temporary, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Vulnerability Response Manager - Apple Information Security

Apple

Austin, TX

$212K - $319K/yr

Full-time

Medical, Dental, Retirement

Re-posted 14 days ago


Apple rating

8.0

Company rating: 8.0 out of 10

Based on 677 frontline employees who took The Breakroom Quiz

7th of 30 rated technology retailers


Job description

Apple Information Security is seeking an experienced security engineering manager to lead the Vulnerability Response team across the United States and EMEIA regions. Apple's external perimeter spans thousands of services relied upon by billions of users worldwide, and this team is responsible for continuously identifying, analyzing, and remediating vulnerabilities across that surface. You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule development, emerging threat response, and custom security
tooling.
You will play a critical role in protecting Apple's services and customers by ensuring timely and thorough response to security risks, fostering engineering excellence, and driving strategic initiatives that strengthen Apple's overall security posture. This role is both strategic and operational, requiring deep technical expertise, strong leadership, and the ability to manage a geographically distributed team operating in a continuous response environment.
Description
As a manager on the Vulnerability Response team, you will lead the day-to-day operations of security engineers across the US and EMEIA regions, as well as oversee resources providing around-the-clock support. You will set team priorities, drive execution across multiple concurrent programs, and ensure operational continuity for a function that requires uninterrupted coverage. This includes direct participation in on-call escalation rotations, hands-on technical contributions such as penetration testing, variant analysis, security tool development, and strategic planning to evolve the team's capabilities over time.
You will partner closely with teams across Apple to ensure coordinated and effective vulnerability response. You will represent the team in cross-functional forums, advocate for security improvements with engineering leadership, and contribute to the development of policies, processes, and tooling that scale the team's impact. You will also maintain the professional standards and reputation through oversight of researcher engagement,
vulnerability adjudication, and program communications.","responsibilities":"Team Leadership: Lead, mentor, and grow a geographically distributed team of security engineers across the US and EMEIA regions. Set goals, support professional development, and oversee resources providing around-the-clock Tier 1 support.
Vulnerability Response Operations: Own the team's continuous vulnerability response function, including on-call escalation, emerging threat and zero-day assessment, and coordination of rapid remediation efforts across Apple's external perimeter.
Vulnerability Discovery and Remediation: Drive proactive security assessment programs, including penetration testing, variant analysis, and large-scale scanning initiatives, to identify and remediate vulnerabilities before they are discovered or exploited by external parties.
Security Program Management: Manage the lifecycle of external researcher engagement, report validation, risk assessment, and remediation coordination.
Security Tooling and Automation: Guide the development and maintenance of custom security tools and automation that support vulnerability detection, analysis, and remediation tracking at scale, including the application of emerging technologies to increase operational efficiency.
Cross-Functional Collaboration: Serve as a trusted security advisor to engineering, product, and leadership teams, partnering across security and infrastructure organizations to align vulnerability response priorities with broader security objectives and drive adoption of security improvements.
Preferred Qualifications
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
Experience with cloud-native architectures, WAF technologies, and DNS security disciplines, with the ability to assess security implications across modern deployment and infrastructure environments.
Background in applying AI and machine learning techniques to security operations, including automated analysis, classification, or remediation workflows.
Relevant industry certifications such as CISSP, OSCP, OSCE, GPEN, or equivalent are helpful but not required.
Minimum Qualifications
8+ years of experience in information security, with demonstrated expertise in vulnerability management, web application penetration testing, and incident response for large-scale internet-facing services, including 3+ years of people management experience leading and developing teams of security engineers.
Strong technical proficiency in web application security, including hands-on experience identifying and remediating common vulnerability classes, and software development skills in one or more of Python, Go, or Bash.
Experience managing or contributing to a vulnerability disclosure or bug bounty program, including researcher engagement, vulnerability validation, and coordinated disclosure processes.
Experience with vulnerability scanning tools and methodologies at enterprise scale, including both commercial and open-source solutions.
Demonstrated ability to manage geographically distributed teams across multiple time zones, with willingness to participate in on-call rotations, including weekends, as part of a tiered escalation model.
Excellent written and verbal communication skills, with the ability to articulate complex security issues and risk to both technical and non-technical audiences.
Pay & Benefits
At Apple, base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay range for this role is between $212,600 and $319,800, and your base pay will depend on your skills, qualifications, experience, and location.
Apple employees also have the opportunity to become an Apple shareholder through participation in Apple's discretionary employee stock programs. Apple employees are eligible for discretionary restricted stock unit awards, and can purchase Apple stock at a discount if voluntarily participating in Apple's Employee Stock Purchase Plan. You'll also receive benefits including: Comprehensive medical and dental coverage, retirement benefits, a range of discounted products and free services, and for formal education related to advancing your career at Apple, reimbursement for certain educational expenses - including tuition. Additionally, this role might be eligible for discretionary bonuses or commission payments as well as relocation. Learn more about Apple Benefits
Note: Apple benefit, compensation and employee stock programs are subject to eligibility requirements and other terms of the applicable plan or program.

What Apple employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Apple logo

About Apple

Sourced by ZipRecruiter

Imagine what you could do here! At Apple, new ideas have a way of becoming extraordinary products, services, and customer experiences very quickly. Bring passion and dedication to your job and there's no telling what you could accomplish. Dynamic, intelligent people and inspiring, innovative technologies are the norm here. The people who work here have reinvented entire industries with all Apple Hardware products. The same real passion for innovation that goes into our products also applies to our practices strengthening our dedication to leave the world better than we found it.

Industry

Computer and electronic product manufacturing

Company size

10,000+ Employees

Headquarters location

Cupertino, CA, US

Year founded

1976