... Remote Code Execution. * Safely validate and exploit discovered vulnerabilities while following ... Participate in ongoing bug bounty programs and private security research engagements. * Share ...
... Remote Code Execution. * Safely validate and exploit discovered vulnerabilities while following ... Participate in ongoing bug bounty programs and private security research engagements. * Share ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
What you'll do: * Own and scale Mozilla's web bug bounty program, including strategy ... D #LI-REMOTE Req ID: R3105
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
What you'll do: * Own and scale Mozilla's web bug bounty program, including strategy ... D #LI-REMOTE Req ID: R3105
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
What you'll do: * Own and scale Mozilla's web bug bounty program, including strategy ... D #LI-REMOTE Req ID: R3105 Hiring Ranges: US Tier 1 Locations $137,000-$183,000 USD US Tier 2 ...
Senior Security Engineer, Bug Bounty
$117K - $160K/yr
What you'll do: * Own and scale Mozilla's web bug bounty program, including strategy ... D #LI-REMOTE Req ID: R3105 Hiring Ranges: US Tier 1 Locations $137,000-$183,000 USD US Tier 2 ...
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$320K - $485K/yr
Evolve a public bug bounty program where automation handles routine triage and root-cause work, and engineers handle escalations and corner cases * Partner with Product, Infrastructure, and Research ...
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$320K - $485K/yr
Evolve a public bug bounty program where automation handles routine triage and root-cause work, and engineers handle escalations and corner cases * Partner with Product, Infrastructure, and Research ...
This includes hands-on ownership of Vercel's open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right ...
This includes hands-on ownership of Vercel's open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right ...
Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad ... Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.
Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad ... Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.
Our dedication to remote-first work, and strong culture of connection and global inclusion means ... Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad ...
Our dedication to remote-first work, and strong culture of connection and global inclusion means ... Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad ...
Cybersecurity Engineer (Remote)
Lehi, UT · On-site +1
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Cybersecurity Engineer (Remote)
Lehi, UT · On-site +1
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Quick apply
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...
This is a US remote position reporting directly to the Director of our Security Engineering team ... rigorous, agent enabled cross-brand Bug Bounty Program, Penetration Testing Program and ...
This is a US remote position reporting directly to the Director of our Security Engineering team ... rigorous, agent enabled cross-brand Bug Bounty Program, Penetration Testing Program and ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...
Senior Security Engineer - Product Security
$117K - $160K/yr
You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native ...
Product Security Engineer
San Francisco, CA · On-site +1
If you're located beyond that distance, the role is fully remote. For location-specific details ... Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement ...
Product Security Engineer
San Francisco, CA · On-site +1
If you're located beyond that distance, the role is fully remote. For location-specific details ... Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement ...
Manager, Security Engineering
San Francisco, CA · On-site +1
... including managing our bug bounty program * Security Architecture Review: Collaborate with ... Remote US or Canada Full-Time Employees at Cohere enjoy these Perks: * A weekly lunch stipend of ...
Manager, Security Engineering
San Francisco, CA · On-site +1
... including managing our bug bounty program * Security Architecture Review: Collaborate with ... Remote US or Canada Full-Time Employees at Cohere enjoy these Perks: * A weekly lunch stipend of ...
Remote - within the United States This is a fully remote role. Candidates must be authorized to ... Public vulnerability disclosures Participation in bug bounty programs Security research ...
Remote - within the United States This is a fully remote role. Candidates must be authorized to ... Public vulnerability disclosures Participation in bug bounty programs Security research ...
Security Engineer
San Francisco, CA · Remote
Help run penetration testing, offensive security exercises, and support our bug bounty program ... Remote
Security Engineer
San Francisco, CA · Remote
Help run penetration testing, offensive security exercises, and support our bug bounty program ... Remote
Member of Technical Staff (Software Engineer, Security)
New York, NY · On-site +1
$220K - $405K/yr
Develop and operate systems and workflows that support the bug bounty and vulnerability disclosure program, including intake, triage, prioritization, and remediation tracking. * Partner with product ...
Member of Technical Staff (Software Engineer, Security)
New York, NY · On-site +1
$220K - $405K/yr
Develop and operate systems and workflows that support the bug bounty and vulnerability disclosure program, including intake, triage, prioritization, and remediation tracking. * Partner with product ...
Respond to and triage reports from bug bounty programs. Minimum Qualifications * B.S. or M.S. in Computer Science, a related technical field, or equivalent experience. * 3+ years of experience in ...
Respond to and triage reports from bug bounty programs. Minimum Qualifications * B.S. or M.S. in Computer Science, a related technical field, or equivalent experience. * 3+ years of experience in ...
... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...
... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...
... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...
... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...
Remote Bug Bounty Program information
See salary details
$16.35 - $22.01
6% of jobs
$22.01 - $27.67
14% of jobs
$31.30 is the 25th percentile. Wages below this are outliers.
$27.67 - $33.33
7% of jobs
$33.33 - $38.99
1% of jobs
$38.99 - $44.65
13% of jobs
The median wage is $47.88 / hr.
$44.65 - $50.31
15% of jobs
$50.31 - $55.97
3% of jobs
$55.97 - $61.63
9% of jobs
$65.30 is the 75th percentile. Wages above this are outliers.
$61.63 - $67.29
11% of jobs
$67.29 - $72.95
15% of jobs
$72.95 - $78.61
6% of jobs
$16
$49
$78
How much do remote bug bounty program jobs pay per hour?
What is a remote bug bounty program?
What skills and qualifications are needed to thrive in a remote bug bounty program?
What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?
What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?
| Aspect | Remote Bug Bounty Program | Remote Penetration Tester |
|---|---|---|
| Credentials | Typically no formal certifications required, but cybersecurity knowledge helps | Often holds certifications like OSCP, CEH, or CISSP |
| Work Environment | Participates remotely, often independently, on various platforms | Works remotely or on-site for clients, conducting security assessments |
| Employer & Industry Usage | Used by companies to crowdsource security testing; industry-wide | Employed by organizations or consulting firms to perform security audits |
While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.
What cities are hiring for Remote Bug Bounty Program jobs?
Cities with the most Remote Bug Bounty Program job openings:
What are the most commonly searched types of Bug Bounty Program jobs?
The most popular types of Bug Bounty Program jobs are:
What states have the most Remote Bug Bounty Program jobs?
States with the most job openings for Remote Bug Bounty Program jobs include:
What job categories do people searching Remote Bug Bounty Program jobs look for?
The top searched job categories for Remote Bug Bounty Program jobs are:

Bug Bounty Security Researcher
On-site, Remote
Contractor
Posted 9 days ago
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Bug Bounty Security Researcher based in Netherlands.
This is an exciting security research opportunity for a skilled professional passionate about discovering vulnerabilities and strengthening real-world application security.
You will investigate software applications, systems, and networks to uncover security weaknesses before they can be exploited maliciously.
The role combines offensive security research, creative attack development, vulnerability exploitation, and detailed technical reporting.
You will work across web, mobile, and network security environments while participating in private and public bug bounty programs.
Your findings will directly contribute to improving security products and services and protecting customers against emerging threats.
The position offers flexibility to work independently, explore challenging targets, and be rewarded for high-impact vulnerabilities.
This opportunity is ideal for a curious and analytical security researcher who enjoys continuous learning and responsible vulnerability disclosure.
- Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.
- Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.
- Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.
- Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.
- Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.
- Participate in ongoing bug bounty programs and private security research engagements.
- Share security findings and insights that can help improve products, services, and overall vulnerability management practices.
- Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.
- Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.
Requirements
- At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.
- Strong understanding of computer systems, networks, web applications, and software security.
- Practical knowledge of offensive security methodologies and vulnerability discovery techniques.
- Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
- Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.
- Experience participating in bug bounty programs and applying responsible disclosure practices.
- Strong analytical, investigative, and problem-solving abilities.
- Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.
- Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.
- 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.
- A recognized public bug bounty profile with awarded vulnerability reports is preferred.
- Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.
- Strong sense of responsibility and commitment to ethical security research.
Benefits
- Flexible freelance engagement allowing you to work according to your own schedule.
- Bounty awards for valid and accepted vulnerability reports.
- Weekly payments for valid reports following successful triage.
- Recognition for high-quality submissions through leaderboards both on and outside the platform.
- Opportunities to perform real-world penetration testing across web application, mobile, and network security.
- Access to private and exclusive bug bounty programs.
- Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.
- Collaborative, empathy-led security culture focused on improving internet security.
- Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.