2

Remote Bug Bounty Program Jobs in Idaho (NOW HIRING)

Application Security Engineer

Post Falls, ID · On-site +1

$175K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This is a remote position, but if you're near one of our local offices, you're welcome to come ... party bug bounty program pen tester, or in a similar security type role. Your job will be to ...

Remote Bug Bounty Program information

What is a remote bug bounty program?

Remote Bug Bounty Programs are initiatives run by organizations that invite independent security researchers, or 'bug hunters,' to find and report vulnerabilities in their software or systems. These programs are conducted entirely online, allowing participants from around the world to contribute remotely. Companies offer monetary rewards or other incentives for valid and impactful security findings. This approach helps organizations strengthen their security by leveraging a global pool of ethical hackers, while participants gain recognition and compensation for their expertise.

What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?

One of the main challenges in remote bug bounty programs is staying motivated and disciplined without direct oversight, as participants often work independently. Additionally, understanding the specific security requirements and scope of each program can be complex, especially when dealing with varied platforms and reporting standards. To overcome these challenges, it's important to set personal goals, join online communities for peer support, and thoroughly review each program's documentation before starting. Effective communication with program coordinators can also help clarify expectations and facilitate successful submissions.

What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?

AspectRemote Bug Bounty ProgramRemote Penetration Tester
CredentialsTypically no formal certifications required, but cybersecurity knowledge helpsOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentParticipates remotely, often independently, on various platformsWorks remotely or on-site for clients, conducting security assessments
Employer & Industry UsageUsed by companies to crowdsource security testing; industry-wideEmployed by organizations or consulting firms to perform security audits

While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.

What skills and qualifications are needed to thrive in a remote bug bounty program?

To thrive in a Remote Bug Bounty Program role, you need a strong background in cybersecurity, vulnerability assessment, and ethical hacking, often supported by experience in penetration testing and security certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential. Attention to detail, persistence, effective communication, and self-motivation are standout soft skills for this position. These abilities are crucial for identifying and responsibly reporting security vulnerabilities that help organizations strengthen their defenses.

What are popular job titles related to Remote Bug Bounty Program jobs in Idaho?

For Remote Bug Bounty Program jobs in Idaho, the most frequently searched job titles are:

What job categories do people searching Remote Bug Bounty Program jobs in Idaho look for?

The top searched job categories for Remote Bug Bounty Program jobs in Idaho are:

What cities in Idaho are hiring for Remote Bug Bounty Program jobs?

Cities in Idaho with the most Remote Bug Bounty Program job openings:

Application Security Engineer

Corporate Tools

Post Falls, ID • On-site, Remote

$175K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 4 days ago


Job description

Overview
Corporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a remote position, but if you're near one of our local offices, you're welcome to come hangout with us in-office as well. Our main offices are in Post Falls, ID, and Spokane, WA; we also have satellite offices in Austin, TX, and Salt Lake City, UT. You'll be working 40 hours a week and, of course, enjoy great company benefits.
We are expanding our team to include a Security Engineer to be 100% focused on our security efforts. As the right candidate, you will have experience working in-house as a full-time penetration tester, a regular 3rd party bug bounty program pen tester, or in a similar security type role. Your job will be to identify our vulnerabilities to help keep our information safe and secure.
Wage
Up to $175,000 / year
Benefits
  • 100% employer-paid medical, dental and vision for employees
  • Annual review with raise option
  • 22 days Paid Time Off accrued annually, and 4 holidays
    • After 3 years, PTO increases to 29 days. Employees transition to flexible time off after 5 years with the company-not accrued, not capped, take time off when you want
    • The 4 holidays are: New Year's Day, Fourth of July, Thanksgiving, and Christmas Day
  • Paid Parental Leave
  • Up to 6% company matching 401(k) with no vesting period
  • Quarterly allowance
    • Use to make your remote work set up more comfortable, for continuing education classes, a plant for your desk, coffee for your coworker, a massage for yourself... really, whatever
  • Open concept office with friendly coworkers
  • Creative environment where you can make a difference
  • No dumb benefits like free dog walking on the weekends that snobby hipster places have to make you feel cool, but mathematically won't cost the company much money because you won't use it
  • Trail Mix Bar - oh yeah

Responsibilities
  • Understand and safely use various open source penetration testing tools and when appropriate, emulating hacker tactics, techniques, procedures
  • Create security vulnerability reports for both technical and executive audiences
  • While in-between assessments, you will be expected to help our security engineers think through solutions to problems you find
  • Automate tasks and script at a basic level to enhance penetration testing processes
  • Passion for learning new technologies and processes, and contributing to refining existing capabilities
  • Communicate with stakeholders (technical and non-technical), both verbal and written
  • Stay up to date on 0 day exploits for tech stacks we use

Requirements
  • Solid fundamentals in webapp and network pentesting (2+ years). Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus
  • 4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent framework
  • Experience with Linux and cloud environment testing
  • Understanding of security issues for desktop, virtual, cloud services and network infrastructures
  • Working knowledge of information systems security standards/practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)
  • Experience with secure network protocols and encryption of communications between networked hosts
  • Experience in IT systems and security policies, standards, industry trends, and techniques
  • Experience with assessing APT threats, Penetration Testing, Vulnerability Management, attack methodologies, forensics analysis techniques, malware analysis, attack surface comprehension, Cyber Threat Emulation operations, Cyber Advanced Threat Emulation Team operations and research, identification, and/or verification of new APT TTPs
  • Fundamental understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systems
  • Must be detail-oriented and possess strong problem-solving skills and ability to analyze for potential future issues
  • Solid understanding of common webapp vulnerabilities, exploitation techniques, and remediation options