1

Overnight Bug Bounty Program Jobs (NOW HIRING)

Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of ...

NY · On-site

$120 - $150/hr

Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. * Collaborate with Dev/QA teams throughout the ...

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Shape Persona's presence in the security research community -- running the bug bounty program that powers it. Must-haves * 4+ years of software engineering experience. * 2+ years in product security.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Red Team Engineer/ Offensive Security Lead

$104K - $138K/yr

You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program. If you've spent years thinking like an adversary and you ...

Showing results 41-60

Overnight Bug Bounty Program information

See salary details

$16

$49

$78

How much do overnight bug bounty program jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for overnight bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is an overnight bug bounty program?

An Overnight Bug Bounty Program is a cybersecurity initiative where companies invite ethical hackers to identify and report security vulnerabilities in their systems during a designated overnight period. These programs are often time-limited and focus on rapid discovery and remediation of critical issues while minimizing disruption to business operations. Participants are rewarded based on the severity and validity of the bugs they report, helping organizations improve their security posture quickly. This approach leverages the fresh perspective and expertise of the broader security community in a concentrated timeframe.

What are the key skills and qualifications needed to thrive as an overnight bug bounty program participant?

To excel in an Overnight Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, ethical hacking techniques, and vulnerability assessment, often backed by practical experience or relevant certifications such as CEH or OSCP. Familiarity with tools like Burp Suite, Metasploit, Nmap, and bug bounty platforms such as HackerOne or Bugcrowd is essential. Attention to detail, persistence, and clear written communication set top performers apart in this field. These skills and qualities are crucial to effectively identify, document, and report security flaws, ensuring both personal success and improved security for participating organizations.

What are the typical challenges faced when working in an overnight bug bounty program role?

Working overnight in a bug bounty program often involves managing the difficulties of non-traditional hours, such as adjusting your sleep schedule and maintaining focus during late-night shifts. You may also encounter challenges in effectively communicating with global teams or program managers who operate during standard business hours. Additionally, handling urgent vulnerability reports and ensuring timely responses can be demanding, but it offers the opportunity to develop strong problem-solving skills and build a reputation in the cybersecurity community. Collaboration with other security researchers and clear documentation are key to success in this dynamic environment.
More about Overnight Bug Bounty Program jobs

What cities are hiring for Overnight Bug Bounty Program jobs?

Cities with the most Overnight Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Overnight Bug Bounty Program jobs?

States with the most job openings for Overnight Bug Bounty Program jobs include:

What job categories do people searching Overnight Bug Bounty Program jobs look for?

The top searched job categories for Overnight Bug Bounty Program jobs are:

Infographic showing various Overnight Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Security Engineer, Application Security at Mercor Alabaster New York, NY

Fairweather, LLC

Manhattan, NY • On-site

$140 - $200/hr

Other

Medical, Dental, Vision

Posted 4 days ago


Job description

Mercor Alabaster. New York, NY.

Security Engineer, Application Security job at Mercor. Mercor's mission is to organize human intelligence to power the AI economy. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $3 million a day. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You'll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build:
  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
  • Vulnerability management processes that prioritize by real exploitability, not CVSS score
  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
What We're Looking For
  • You've found and fixed real vulnerabilities in production applications - not just run scanners
  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Bonus Points
  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills - you've done penetration testing and can think like an attacker
  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
  • You've built custom security tooling that a team still uses
  • Contributions to open source security projects or published vulnerability research
Why Mercor
  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
  • Benefits
    • Bi-annual performance bonus structure
    • Generous equity grant vested over 4 years
    • Up to $15k Relocation bonus
    • $10K housing bonus (if you live within 0.5 miles of our office)
    • $1.5K monthly stipend for meals
    • Free Equinox membership
    • $200 monthly laundry reimbursement
    • $200 monthly personal wellness reimbursement
    • Health, Dental, Vision insurance
#J-18808-Ljbffr