1

On Call Bug Bounty Program Jobs (NOW HIRING)

NY ยท On-site

$120 - $150/hr

Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. * Collaborate with Dev/QA teams throughout the ...

Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of ...

Senior Product Security Engineer

Austin, TX ยท On-site

$180 - $240/hr

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Product Security Engineer

San Francisco, CA ยท On-site

$120 - $160/hr

Shape Persona's presence in the security research community -- running the bug bounty program that powers it. Must-haves * 4+ years of software engineering experience. * 2+ years in product security.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

$81 - $128/hr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

New

The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...

Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions

Manager, Security Engineering

San Francisco, CA ยท On-site +1

$320K - $385K/yr

Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...

The role partners with AI governance, development teams, and external specialists (including consultants and bug bounty programs) to ensure comprehensive adversarial coverage of the Company's AI ...

Showing results 41-60

On Call Bug Bounty Program information

See salary details

$16

$49

$78

How much do on call bug bounty program jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for on call bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is an On Call Bug Bounty Program?

An On Call Bug Bounty Program is a security initiative where organizations invite ethical hackers to find and report vulnerabilities in their systems on an as-needed or on-call basis. Unlike traditional bug bounty programs, this model may involve a select group of trusted researchers who are contacted to test specific features or during particular timeframes. It helps organizations quickly identify and address critical security risks, often before public launch or after significant updates. Participants receive rewards or recognition for valid vulnerability submissions, supporting a proactive approach to cybersecurity.

What are the key skills and qualifications needed to thrive as an On Call Bug Bounty Program participant?

To thrive in an On Call Bug Bounty Program, you need strong knowledge of cybersecurity principles, vulnerability assessment, and hands-on experience in penetration testing, typically demonstrated through relevant certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and bug tracking platforms is essential for efficiently identifying and reporting security flaws. Attention to detail, persistence, and strong written communication skills help you document findings and collaborate with program stakeholders. These competencies are vital to ensure vulnerabilities are accurately detected and responsibly disclosed to protect organizational assets.

What are the main challenges faced by professionals working in an On Call Bug Bounty Program role?

Professionals in On Call Bug Bounty Program roles often encounter challenges such as managing unpredictable workloads, rapidly assessing and triaging incoming vulnerability reports, and maintaining effective communication with both internal security teams and external researchers. The on-call aspect can require quick decision-making and adaptability, especially when critical issues arise outside of regular hours. Additionally, staying updated on the latest security threats and vulnerabilities is essential to effectively prioritize and address reported bugs.

What is the difference between On Call Bug Bounty Program vs Penetration Tester?

AspectOn Call Bug Bounty ProgramPenetration Tester
CredentialsNone required; often self-taught or certified in security basicsCertifications like OSCP, CEH, or CISSP typically required
Work EnvironmentRemote, flexible, project-basedOften on-site or hybrid, structured engagements
Employer & Industry UsageCompanies seeking external security testing via crowdsourcingSecurity firms or internal teams conducting authorized testing
Search & Comparison IntentUnderstanding freelance or crowdsourced security testing optionsProfessional security assessment roles

The On Call Bug Bounty Program involves independent security researchers testing applications remotely on a project basis, often without formal employment. Penetration Testers are typically employed or contracted professionals with certifications, performing structured security assessments. Both roles focus on identifying vulnerabilities but differ in credentials, work environment, and engagement style.

How to start a career in on call bug bounty program?

To start a career in an on call bug bounty program, develop skills in web and application security, learn common vulnerability types, and familiarize yourself with bug bounty platforms like HackerOne or Bugcrowd. Gaining experience through practice, participating in bug bounty programs, and obtaining relevant certifications such as OSCP or CEH can improve your chances of success.
More about On Call Bug Bounty Program jobs

What cities are hiring for On Call Bug Bounty Program jobs?

Cities with the most On Call Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

Infographic showing various On Call Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 18% Part Time, and 4% Contract. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Application Security Engineer

Softswiss

NY โ€ข On-site

$120 - $150/hr

Other

Medical, PTO

Posted 17 days ago


Key responsibilities

  • Partner with product teams during the design phase to facilitate threat modeling and risk assessment sessions.

  • Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box security assessments.

  • Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws.


Job description

Security | Application Security Engineer

SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we would love to hear from you.

Purpose of the role

Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers.

As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products.

Key responsibilities
  • Partner with product teams during the design phase to facilitate threat modeling and risk assessment sessions.
  • Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box security assessments.
  • Tune and adjust rulesets for automated security scanning tools to reduce false positives and improve detection rates.
  • Develop scripts and automation tools to streamline workflows and free up time for more complex analysis.
  • Assist developers in understanding security risks and threats discovered during risk assessments, threat modeling, and dynamic testing.
  • Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws.
  • Collaborate with Dev/QA teams throughout the development lifecycle to enhance the applicationโ€™s security posture by providing dedicated security consulting, continuous knowledge sharing, and actionable guidance.
  • Develop and maintain the internal security knowledge base, including comprehensive secure coding guidelines and technical manuals for standard security features.
Required Experience
  • 3+ years of experience in application security, software development, or related technical roles.
  • Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP).
  • Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical mitigation strategies.
  • Knowledge of secure system and application architecture alongside secure-by-design principles.
  • Practical, handsโ€‘on expertise in identifying vulnerabilities through manual security assessments and secure code reviews.
  • Ability to clearly articulate and explain the business impact of identified threats and vulnerabilities to developers and product teams.
  • A strong securityโ€‘first mindset with a continuous drive to learn and achieve excellence in the cybersecurity field.
  • University degree in Computer Science, Information Security, or a related field (or an equivalent combination of education and practical experience).
  • English and Russian proficiency at an upperโ€‘intermediate level (B2+)
Nice to have
  • Passion about programming.
  • Technical knowledge of network and operating systems security.
  • Practice of participation in bug bounty programs and/or CTFs.
  • Knowledge of SAST/DAST tools, including customization.
Main Advantages
  • Private health insurance
  • Sports benefits
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
#J-18808-Ljbffr