1

On Call Bug Bounty Program Jobs (NOW HIRING)

... our bug bounty program • Partner with engineering teams to design and deploy solutions which are inherently secure • Champion the use of tooling (linters, static analysis, posture assessment ...

Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions

Senior Application Security Engineer

Meridian, ID · Remote

$111K - $152K/yr

Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. * Own and continuously improve application ...

Marketing Lead

San Carlos, CA · On-site

$120 - $160/hr

Own the go‑to‑market strategy for core products, including Managed Triage and Bug Bounty Program Subscriptions. * Define ideal customer profiles, build messaging architectures, and translate ...

The role partners with AI governance, development teams, and external specialists (including consultants and bug bounty programs) to ensure comprehensive adversarial coverage of the Company's AI ...

WI · On-site

$175 - $237/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Build durable working relationships with partner organizations including shared SAST platform teams, application security platforms, and the Bug Bounty program * Establish metrics frameworks and ...

New

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

... our bug bounty program end to end: triage, response, remediation, and researcher communication • Partner with Engineering to embed secure design patterns and security review into how we ship ...

Product Security Engineer

Seattle, WA · On-site

$188K - $250K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Help drive improvements across our Product Security tooling, automation, and bug bounty program. * Experiment with and develop AI-based tools to enable the Security team to move even faster. * Be the ...

CNO Developer

Chantilly, VA · On-site

$129K - $177K/yr

Desire to contribute to CTF events, bug bounty programs, and speaking at the security conferences * Rapid Prototype Software Development Security Clearance: * Active TS/SCI level clearance. Must be ...

Software Security Engineer

Pittsburgh, PA · On-site

$110K - $120K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Build the automation that triages, routes, and reports vulnerability findings, and run our enterprise Bug Bounty program. * Operate and improve Bot Management, WAF, secrets management, and API ...

Showing results 41-60

On Call Bug Bounty Program information

See salary details

$16

$49

$78

How much do on call bug bounty program jobs pay per hour?

As of Aug 14, 2026, the average hourly pay for on call bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is an On Call Bug Bounty Program?

An On Call Bug Bounty Program is a security initiative where organizations invite ethical hackers to find and report vulnerabilities in their systems on an as-needed or on-call basis. Unlike traditional bug bounty programs, this model may involve a select group of trusted researchers who are contacted to test specific features or during particular timeframes. It helps organizations quickly identify and address critical security risks, often before public launch or after significant updates. Participants receive rewards or recognition for valid vulnerability submissions, supporting a proactive approach to cybersecurity.

What are the main challenges faced by professionals working in an On Call Bug Bounty Program role?

Professionals in On Call Bug Bounty Program roles often encounter challenges such as managing unpredictable workloads, rapidly assessing and triaging incoming vulnerability reports, and maintaining effective communication with both internal security teams and external researchers. The on-call aspect can require quick decision-making and adaptability, especially when critical issues arise outside of regular hours. Additionally, staying updated on the latest security threats and vulnerabilities is essential to effectively prioritize and address reported bugs.

What are the key skills and qualifications needed to thrive as an On Call Bug Bounty Program participant?

To thrive in an On Call Bug Bounty Program, you need strong knowledge of cybersecurity principles, vulnerability assessment, and hands-on experience in penetration testing, typically demonstrated through relevant certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and bug tracking platforms is essential for efficiently identifying and reporting security flaws. Attention to detail, persistence, and strong written communication skills help you document findings and collaborate with program stakeholders. These competencies are vital to ensure vulnerabilities are accurately detected and responsibly disclosed to protect organizational assets.

What is the difference between On Call Bug Bounty Program vs Penetration Tester?

AspectOn Call Bug Bounty ProgramPenetration Tester
CredentialsNone required; often self-taught or certified in security basicsCertifications like OSCP, CEH, or CISSP typically required
Work EnvironmentRemote, flexible, project-basedOften on-site or hybrid, structured engagements
Employer & Industry UsageCompanies seeking external security testing via crowdsourcingSecurity firms or internal teams conducting authorized testing
Search & Comparison IntentUnderstanding freelance or crowdsourced security testing optionsProfessional security assessment roles

The On Call Bug Bounty Program involves independent security researchers testing applications remotely on a project basis, often without formal employment. Penetration Testers are typically employed or contracted professionals with certifications, performing structured security assessments. Both roles focus on identifying vulnerabilities but differ in credentials, work environment, and engagement style.

More about On Call Bug Bounty Program jobs

What cities are hiring for On Call Bug Bounty Program jobs?

Cities with the most On Call Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

Infographic showing various On Call Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 1% Temporary, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Security Engineer, Product

Ramp

Remote

Full-time

Re-posted 21 days ago


Job description

Job Summary:
Ramp is building the smart infrastructure for finance teams, automating how businesses manage their financial information. The Product Security team is focused on creating secure products, detecting threats, and ensuring security supports Ramp's growth.
Responsibilities:
• Build security-focused application primitives and integrate them into our existing products
• Design and deploy platform-level mitigations to common security issues
• Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program
• Partner with engineering teams to design and deploy solutions which are inherently secure
• Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure systems more quickly
Qualifications:
Required:
• Minimum of 5 years of experience building software
• Minimum of 2 years of experience focused on platform, infrastructure, and/or security
• Desire to work in a fast-paced environment, continuously grow, and master your craft
• Ability to turn business and product ideas into engineering solutions
• Alignment with Ramp’s core values of enabling businesses to grow more by spending less
Preferred:
• Experience with Python (Flask), Elixir, and AWS (ECS, as well as other core services)
• Experience analyzing and improving the security posture of infrastructure in AWS
Company:
Ramp is a financial technology company that develops software for corporate spend management, finance operations, and business payments. Founded in 2019, the company is headquartered in New York, USA, with a team of 1001-5000 employees. The company is currently Late Stage.