2

Remote Bug Bounty Program Jobs in Oregon (NOW HIRING)

Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. * Security Automation : Develop and implement ...

Principal Application Security Engineer

OR ยท Remote

$58.75 - $78.50/hr

This role can be fully remote and must reside in US. In this role, you will help us drive our ... Drive our security assessment, penetration testing and bug bounty programs * Participate in ...

Senior Offensive Security Engineer

OR ยท On-site +1

$114K - $156K/yr

... program and encourage participation. * Receive and triage vulnerability reports submitted by external researchers through various channels, such as email, web form, or bug bounty platform.

Senior Application Security Engineer

OR ยท Remote

$114K - $156K/yr

... remote environment. * Self-driven and proactive, comfortable operating in a high-autonomy ... Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ...

Engineering Project and QA Manager

OR ยท Remote

$140K - $178K/yr

Remote (United States, Europe, Canada, or LATAM) Role Type: Full-Time Reporting to: VP of ... CodePath's educational programs run on our learning platform, a set of applications spanning ...

Senior Back End Developer

OR ยท Remote

$125K - $180K/yr

... programs across national security, defense, and public service delivery. Recent contract awards in ... This position is remote and requires an active Secret clearance. Active TS/SCI highly preferred.

Senior Front-End Developer

OR ยท Remote

$125K - $150K/yr

This role is remote and requires a Secret clearance or higher. Active TS/SCI highly preferred ... programs/projects. * Practical experience developing in a cloud environment. * 5 years of ...

Front End Developer - Mid-level

OR ยท Remote

$100K - $160K/yr

... programs across national security, defense, and public service delivery. Recent contract awards in ... This role is remote. Active Secret Clearance or above required. Active TS/SCI highly preferred.

Remote Bug Bounty Program information

What are Remote Bug Bounty Programs?

Remote Bug Bounty Programs are initiatives run by organizations that invite independent security researchers, or 'bug hunters,' to find and report vulnerabilities in their software or systems. These programs are conducted entirely online, allowing participants from around the world to contribute remotely. Companies offer monetary rewards or other incentives for valid and impactful security findings. This approach helps organizations strengthen their security by leveraging a global pool of ethical hackers, while participants gain recognition and compensation for their expertise.

What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?

One of the main challenges in remote bug bounty programs is staying motivated and disciplined without direct oversight, as participants often work independently. Additionally, understanding the specific security requirements and scope of each program can be complex, especially when dealing with varied platforms and reporting standards. To overcome these challenges, it's important to set personal goals, join online communities for peer support, and thoroughly review each program's documentation before starting. Effective communication with program coordinators can also help clarify expectations and facilitate successful submissions.

What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?

AspectRemote Bug Bounty ProgramRemote Penetration Tester
CredentialsTypically no formal certifications required, but cybersecurity knowledge helpsOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentParticipates remotely, often independently, on various platformsWorks remotely or on-site for clients, conducting security assessments
Employer & Industry UsageUsed by companies to crowdsource security testing; industry-wideEmployed by organizations or consulting firms to perform security audits

While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.

What are the key skills and qualifications needed to thrive in a Remote Bug Bounty Program role, and why are they important?

To thrive in a Remote Bug Bounty Program role, you need a strong background in cybersecurity, vulnerability assessment, and ethical hacking, often supported by experience in penetration testing and security certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential. Attention to detail, persistence, effective communication, and self-motivation are standout soft skills for this position. These abilities are crucial for identifying and responsibly reporting security vulnerabilities that help organizations strengthen their defenses.
What are the most commonly searched types of Bug Bounty Program jobs in Oregon? The most popular types of Bug Bounty Program jobs in Oregon are:
What job categories do people searching Remote Bug Bounty Program jobs in Oregon look for? The top searched job categories for Remote Bug Bounty Program jobs in Oregon are:
What cities in Oregon are hiring for Remote Bug Bounty Program jobs? Cities in Oregon with the most Remote Bug Bounty Program job openings:

Senior Product Security Engineer

Tines

OR โ€ข On-site, Remote

Other

Posted 18 days ago


Job description

The Role

We're seeking aย Senior Product Security Engineerย who is passionate about building and scaling robust security programs in an AI-forward engineering environment. Reporting to our Head of IT Operations & Information Security, you'll lead efforts to mature our product security initiatives at a pivotal moment of product expansion, ensuring security keeps pace as our developers increasingly leverage AI in their workflows.

A core part of this role is using AI and automation as force multipliers, building security tooling, guardrails, and review processes that scale to match the velocity of AI-assisted development across our engineering org.

This position can be based remotely in the United States.

Key Responsibilities
  • Product Security Leadership: Partner with product and engineering teams to integrate security throughout the development lifecycle and drive security initiatives across our stack.
  • AI-Augmented Security: Leverage AI and automation to scale product security coverage, matching the pace of AI-assisted development across engineering.
  • Security Architecture: Design and implement security controls and architecture that scale with our growing product portfolio.
  • Threat Modeling & Risk Assessment: Conduct comprehensive security reviews and threat modeling to identify and mitigate potential vulnerabilities, including risks introduced by AI-generated code and AI-powered features.
  • Vulnerability Management: Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts.
  • Security Automation: Develop and implement automated security testing, monitoring, and response capabilities, using Tines itself, plus AI-driven tooling, to eliminate manual toil.
  • Security Incident Response: Serve as an incident responder during security events and lead post-incident reviews.
  • Security Education: Champion security awareness and provide technical guidance to engineering teams, including best practices for secure AI-assisted development.
Qualifications
  • 8+ years of experienceย in application or product security roles, with demonstrated expertise in securing cloud-native applications.
  • Strong understanding of modern application security principles, OWASP Top 10, and secure SDLC practices.
  • Experience leveragingย AI and automationย to scale security programs (e.g., LLM-assisted code review, automated triage, agentic security workflows).
  • Experience with cloud security (AWS preferred) and securing containerized environments (Docker, Kubernetes).
  • Proficiency in modern programming languages; experience withย Ruby, TypeScript, and/or Rustย is highly desirable.
  • Knowledge of security testing methodologies and tools (SAST, DAST, SCA).
  • Experience with CI/CD security integration and DevSecOps practices.
  • Strong incident response skills and experience participating in on-call rotations.
  • Excellent communication skills with ability to translate complex security concepts to diverse audiences.
  • Self-motivated with exceptional analytical thinking and problem-solving abilities.
Nice to Haves
  • Experience securingย AI/ML systems and LLM-powered featuresย (prompt injection, model abuse, data leakage, agentic system risks).
  • Familiarity withย LLM red-teaming, AI threat modeling frameworks (e.g., MITRE ATLAS, OWASP LLM Top 10), and emerging AI security standards.
  • Hands-on experience buildingย agentic or automated security workflowsย (using Tines or similar platforms).
  • Contributions to open-source security tooling or active participation in the security research community (CVEs, conference talks, published research).
  • Experience designingย secure-by-default developer platforms, paved roads, or golden paths for engineering teams.
  • Background inย bug bounty triageย at scale, or running a public VDP/bug bounty program.
  • Familiarity withย multi-tenant SaaS securityย challenges (tenant isolation, authz models, data segregation).
  • Experience supporting FedRAMP (Moderate/High) and/or DoD Impact Level (IL4/IL5/IL6) environments.
  • Prior experience at a high-growth startup launching new products or expanding into new product lines.

Target Annual Compensation: $218-$235k + equity

Applicants for this opportunity must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.