2

Remote Bug Bounty Program Jobs in Seattle, WA (NOW HIRING)

Senior Application Security Engineer

Seattle, WA · On-site +1

$66.75 - $89.25/hr

... bug bounty program experience * Production software engineering background * Certifications such as CSSLP, CISSP, OSWA, OSWE, GWAPT, or GMOB Nordstrom is able to offer remote employment of this ...

Software Engineer 3

Bellevue, WA · On-site +1

$65 - $87.25/hr

Participate in the development, testing, release, triage, bug fix, documentation and rest of the ... Remote roles are not eligible for U.S. visa sponsorship. eBay is an equal opportunity employer. All ...

Remote Bug Bounty Program information

See Seattle, WA salary details

$18

$56

$89

How much do remote bug bounty program jobs pay per hour?

As of Jul 29, 2026, the average hourly pay for remote bug bounty program in Seattle, WA is $56.45, according to ZipRecruiter salary data. Most workers in this role earn between $36.11 and $76.06 per hour, depending on experience, location, and employer.

What are Remote Bug Bounty Programs?

Remote Bug Bounty Programs are initiatives run by organizations that invite independent security researchers, or 'bug hunters,' to find and report vulnerabilities in their software or systems. These programs are conducted entirely online, allowing participants from around the world to contribute remotely. Companies offer monetary rewards or other incentives for valid and impactful security findings. This approach helps organizations strengthen their security by leveraging a global pool of ethical hackers, while participants gain recognition and compensation for their expertise.

What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?

One of the main challenges in remote bug bounty programs is staying motivated and disciplined without direct oversight, as participants often work independently. Additionally, understanding the specific security requirements and scope of each program can be complex, especially when dealing with varied platforms and reporting standards. To overcome these challenges, it's important to set personal goals, join online communities for peer support, and thoroughly review each program's documentation before starting. Effective communication with program coordinators can also help clarify expectations and facilitate successful submissions.

What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?

AspectRemote Bug Bounty ProgramRemote Penetration Tester
CredentialsTypically no formal certifications required, but cybersecurity knowledge helpsOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentParticipates remotely, often independently, on various platformsWorks remotely or on-site for clients, conducting security assessments
Employer & Industry UsageUsed by companies to crowdsource security testing; industry-wideEmployed by organizations or consulting firms to perform security audits

While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.

What are the key skills and qualifications needed to thrive in a Remote Bug Bounty Program role, and why are they important?

To thrive in a Remote Bug Bounty Program role, you need a strong background in cybersecurity, vulnerability assessment, and ethical hacking, often supported by experience in penetration testing and security certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential. Attention to detail, persistence, effective communication, and self-motivation are standout soft skills for this position. These abilities are crucial for identifying and responsibly reporting security vulnerabilities that help organizations strengthen their defenses.
What are the most commonly searched types of Bug Bounty Program jobs in Seattle, WA? The most popular types of Bug Bounty Program jobs in Seattle, WA are:
What are popular job titles related to Remote Bug Bounty Program jobs in Seattle, WA? For Remote Bug Bounty Program jobs in Seattle, WA, the most frequently searched job titles are:
What job categories do people searching Remote Bug Bounty Program jobs in Seattle, WA look for? The top searched job categories for Remote Bug Bounty Program jobs in Seattle, WA are:
What cities near Seattle, WA are hiring for Remote Bug Bounty Program jobs? Cities near Seattle, WA with the most Remote Bug Bounty Program job openings:
Infographic showing various Remote Bug Bounty Program job openings in Seattle, WA as of July 2026, with employment types broken down into 34% Locum Tenens, 38% Full Time, 8% Part Time, 1% Temporary, 1% Contract, and 18% Summer. Highlights an 88% Physical, 1% Hybrid, and 11% Remote job distribution, with an average salary of $117,420 per year, or $56.5 per hour.
Senior Application Security Engineer

Senior Application Security Engineer

Nordstrom

Seattle, WA • On-site, Remote

$66.75 - $89.25/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 22 days ago


Nordstrom rating

6.8

Company rating: 6.8 out of 10

Based on 423 frontline employees who took The Breakroom Quiz

4th of 21 rated department stores


Job description

Job Description

Senior Application Security Engineer 

Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving fast and shipping securely. As one of the first hires, you’ll build the tooling and secure defaults that protect our web, mobile, and API ecosystem, do the deep work tooling can’t, and help shape how we build with AI. You’ll report to the Senior Manager of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack surface management, and platform. 

A Day in the Life 

  • Build secure-by-default patterns and paved-road tooling so teams get security built into the pipelines and frameworks they already use 

  • Own the AppSec tooling stack (SAST, SCA, secrets scanning, DAST), tune it for signal over noise, and route findings into where engineers already work 

  • Automate the security work that doesn’t need human judgment, and save manual review for the work that does 

  • Partner with our security teams, mentor engineers and champions, and raise the application security bar across the org 

More About You 

  • You’d rather build the guardrail than write the policy, and you’ve shipped tooling that changed how other engineers work 

  • You go looking for the problems worth solving and own them end to end 

  • You’re the security person other teams want in the room, because you explain risk clearly, respect how teams work, and help them find a fix that fits 

  • You think in risk, not severity scores. You know the difference between a finding that’s exploitable in our context and one that just looks scary, and you prioritize accordingly 

Qualifications 

  • 4+ years in application security, secure software development, or a closely related field, with a bachelor’s or master’s in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent experience 

  • A track record shipping security tooling, automation, or reusable patterns, not just operating off-the-shelf tools 

  • Expert-level threat modeling, security design review, and manual code review, with deep knowledge of application and API vulnerability classes and how to design them out 

  • Fluent enough to read and write code in languages like Java, Kotlin, C#, or Python 

  • Hands-on fluency using AI to accelerate real security work, with judgment about where to trust it and where to verify 

  • Working knowledge of how LLM and agent features fail, including prompt injection, unsafe tool and permission use, and data leakage through model outputs 

  • Cloud-native, container, and serverless security (AWS, GCP, Azure, Kubernetes) 

Nice to Have 

  • Hands-on with GitHub Advanced Security and JFrog Artifactory, or similar 

  • Offensive security experience 

  • Vulnerability disclosure or bug bounty program experience 

  • Production software engineering background 

  • Certifications such as CSSLP, CISSP, OSWA, OSWE, GWAPT, or GMOB 
    Nordstrom is able to offer remote employment of this position in all US states except AR, MS, MT, ND, SD, VT, WV, and WY. 


Pay Range Details

The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. 
Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

California: $120,000-$258,000, Colorado: $120,000-$219,500, Connecticut: $120,000-$258,000, Deleware: $120,000-$219,500, Hawaii: $120,000-$219,500, Illinois: $120,000-$219,500, Maine: $120,000-$219,500, Maryland: $120,000-$258,000, Massachusetts: $120,000-$258,000, Minnesota: $120,000-$219,500, Nevada: $120,000-$219,500, New Jersey: $120,000-$258,000, New York: $120,000-$258,000, Rhode Island: $120,000-$219,500, Virginia: $120,000-$258,500, Washington: $120,000-$258,500, Washington DC: $142,000-$258,000

 

 

We’ve got you covered…

Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources

   

This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_17-19.pdf

 

A few more important points...

The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.


For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.


Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com. 


Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.

Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.

 

Nordstrom keeps job postings open for at least one day after the posting date.

 

© 2026 Nordstrom, Inc

What Nordstrom employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom