1

Overnight Bug Bounty Program Jobs (NOW HIRING)

Participate in ongoing bug bounty programs and private security research engagements. * Share security findings and insights that can help improve products, services, and overall vulnerability ...

Technical Program Manager, Bug Bounty

Seattle, WA · On-site

$146K - $190K/yr

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...

Technical Program Manager, Bug Bounty

Seattle, WA · On-site

$146K - $190K/yr

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...

Technical Program Manager, Bug Bounty

Seattle, WA · On-site

$146K - $190K/yr

Amazon's Bug Bounty team is looking for a Technical Program Manager (TPM) to help us secure the services and applications that Amazon customers rely on every day. In this role, you'll drive complex ...

Senior Security Engineer, Bug Bounty

$117K - $160K/yr

Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...

Senior Security Engineer, Bug Bounty

$117K - $160K/yr

Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g ...

Senior Security Engineer

Los Angeles, CA · On-site

$123K - $169K/yr

Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and ...

Bug Bounty Program Management: Own and expand Vercel's bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues ...

You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for ...

Operate the bug bounty program, triage vulnerability reports, and coordinate responses. * Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and ...

next page

Showing results 1-20

Overnight Bug Bounty Program information

See salary details

$16

$49

$78

How much do overnight bug bounty program jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for overnight bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is an overnight bug bounty program?

An Overnight Bug Bounty Program is a cybersecurity initiative where companies invite ethical hackers to identify and report security vulnerabilities in their systems during a designated overnight period. These programs are often time-limited and focus on rapid discovery and remediation of critical issues while minimizing disruption to business operations. Participants are rewarded based on the severity and validity of the bugs they report, helping organizations improve their security posture quickly. This approach leverages the fresh perspective and expertise of the broader security community in a concentrated timeframe.

What are the key skills and qualifications needed to thrive as an overnight bug bounty program participant?

To excel in an Overnight Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, ethical hacking techniques, and vulnerability assessment, often backed by practical experience or relevant certifications such as CEH or OSCP. Familiarity with tools like Burp Suite, Metasploit, Nmap, and bug bounty platforms such as HackerOne or Bugcrowd is essential. Attention to detail, persistence, and clear written communication set top performers apart in this field. These skills and qualities are crucial to effectively identify, document, and report security flaws, ensuring both personal success and improved security for participating organizations.

What are the typical challenges faced when working in an overnight bug bounty program role?

Working overnight in a bug bounty program often involves managing the difficulties of non-traditional hours, such as adjusting your sleep schedule and maintaining focus during late-night shifts. You may also encounter challenges in effectively communicating with global teams or program managers who operate during standard business hours. Additionally, handling urgent vulnerability reports and ensuring timely responses can be demanding, but it offers the opportunity to develop strong problem-solving skills and build a reputation in the cybersecurity community. Collaboration with other security researchers and clear documentation are key to success in this dynamic environment.
More about Overnight Bug Bounty Program jobs

What cities are hiring for Overnight Bug Bounty Program jobs?

Cities with the most Overnight Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Overnight Bug Bounty Program jobs?

States with the most job openings for Overnight Bug Bounty Program jobs include:

What job categories do people searching Overnight Bug Bounty Program jobs look for?

The top searched job categories for Overnight Bug Bounty Program jobs are:

Infographic showing various Overnight Bug Bounty Program job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 1% As Needed, 74% Full Time, 20% Part Time, and 4% Contract. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Bug Bounty Security Researcher

On-site, Remote

Contractor

Posted 9 days ago


Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Bug Bounty Security Researcher based in Netherlands.

This is an exciting security research opportunity for a skilled professional passionate about discovering vulnerabilities and strengthening real-world application security.
You will investigate software applications, systems, and networks to uncover security weaknesses before they can be exploited maliciously.
The role combines offensive security research, creative attack development, vulnerability exploitation, and detailed technical reporting.
You will work across web, mobile, and network security environments while participating in private and public bug bounty programs.
Your findings will directly contribute to improving security products and services and protecting customers against emerging threats.
The position offers flexibility to work independently, explore challenging targets, and be rewarded for high-impact vulnerabilities.
This opportunity is ideal for a curious and analytical security researcher who enjoys continuous learning and responsible vulnerability disclosure.

Accountabilities
  • Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.
  • Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.
  • Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.
  • Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.
  • Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.
  • Participate in ongoing bug bounty programs and private security research engagements.
  • Share security findings and insights that can help improve products, services, and overall vulnerability management practices.
  • Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.
  • Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.

Requirements

  • At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.
  • Strong understanding of computer systems, networks, web applications, and software security.
  • Practical knowledge of offensive security methodologies and vulnerability discovery techniques.
  • Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
  • Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.
  • Experience participating in bug bounty programs and applying responsible disclosure practices.
  • Strong analytical, investigative, and problem-solving abilities.
  • Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.
  • Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.
  • 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.
  • A recognized public bug bounty profile with awarded vulnerability reports is preferred.
  • Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.
  • Strong sense of responsibility and commitment to ethical security research.

Benefits

  • Flexible freelance engagement allowing you to work according to your own schedule.
  • Bounty awards for valid and accepted vulnerability reports.
  • Weekly payments for valid reports following successful triage.
  • Recognition for high-quality submissions through leaderboards both on and outside the platform.
  • Opportunities to perform real-world penetration testing across web application, mobile, and network security.
  • Access to private and exclusive bug bounty programs.
  • Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.
  • Collaborative, empathy-led security culture focused on improving internet security.
  • Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job