2

Remote Bug Bounty Program Jobs (NOW HIRING)

Red Team Engineer/ Offensive Security Lead

$104K - $138K/yr

You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program. If you've spent years thinking like an adversary and you ...

... our bug bounty program • Partner with engineering teams to design and deploy solutions which are inherently secure • Champion the use of tooling (linters, static analysis, posture assessment ...

Senior Security Engineer

$117K - $160K/yr

Preferred : • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and ISO 42001 • Hands-on experience in offensive security (eg, through bug bounty programs or CTFs) Company : Zip is ...

... bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client ... Perks * Flexible work environment - ClickHouse is a globally distributed company and remote ...

Security Engineer

MN · On-site +1

... bug bounty programs (triage, validation, escalation) Exposure to threat modeling and ability to ... Remote VIVA is an equal opportunity employer. All qualified applicants have an equal opportunity ...

Respond to and triage reports from bug bounty programs. Minimum Qualifications * B.S. or M.S. in Computer Science, a related technical field, or equivalent experience. * 3+ years of experience in ...

... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...

... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...

... bug bounty program. • Help respond to product security incidents. • Design and build technical systems to prevent spam, fraud, and abuse. • Partner closely with product teams to identify and ...

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions ... Environment - remote, work-from-home 100% of the time. Pay Range Disclosure At Bugcrowd, we strive ...

... the bug bounty program, including triage, response processes, and improvements to vulnerability management workflows. • Develop security standards, playbooks, and training programs that make ...

Active involvement in cybersecurity communities, research, or bug bounty programs * Certifications ... Flexible work hours with hybrid remote options * Opportunity to work with international ...

Familiarity with vulnerability scanning, penetration testing, and bug bounty/VDP program mechanics. * The "Builder" Edge: You are an active user of AI-native tools (Claude Code, Cursor, etc.) and ...

Showing results 21-40

Remote Bug Bounty Program information

See salary details

$16

$49

$78

How much do remote bug bounty program jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for remote bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is a remote bug bounty program?

Remote Bug Bounty Programs are initiatives run by organizations that invite independent security researchers, or 'bug hunters,' to find and report vulnerabilities in their software or systems. These programs are conducted entirely online, allowing participants from around the world to contribute remotely. Companies offer monetary rewards or other incentives for valid and impactful security findings. This approach helps organizations strengthen their security by leveraging a global pool of ethical hackers, while participants gain recognition and compensation for their expertise.

What skills and qualifications are needed to thrive in a remote bug bounty program?

To thrive in a Remote Bug Bounty Program role, you need a strong background in cybersecurity, vulnerability assessment, and ethical hacking, often supported by experience in penetration testing and security certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential. Attention to detail, persistence, effective communication, and self-motivation are standout soft skills for this position. These abilities are crucial for identifying and responsibly reporting security vulnerabilities that help organizations strengthen their defenses.

What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?

One of the main challenges in remote bug bounty programs is staying motivated and disciplined without direct oversight, as participants often work independently. Additionally, understanding the specific security requirements and scope of each program can be complex, especially when dealing with varied platforms and reporting standards. To overcome these challenges, it's important to set personal goals, join online communities for peer support, and thoroughly review each program's documentation before starting. Effective communication with program coordinators can also help clarify expectations and facilitate successful submissions.

What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?

AspectRemote Bug Bounty ProgramRemote Penetration Tester
CredentialsTypically no formal certifications required, but cybersecurity knowledge helpsOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentParticipates remotely, often independently, on various platformsWorks remotely or on-site for clients, conducting security assessments
Employer & Industry UsageUsed by companies to crowdsource security testing; industry-wideEmployed by organizations or consulting firms to perform security audits

While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.

More about Remote Bug Bounty Program jobs

What cities are hiring for Remote Bug Bounty Program jobs?

Cities with the most Remote Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Remote Bug Bounty Program jobs?

States with the most job openings for Remote Bug Bounty Program jobs include:

What job categories do people searching Remote Bug Bounty Program jobs look for?

The top searched job categories for Remote Bug Bounty Program jobs are:

Infographic showing various Remote Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Red Team Engineer/ Offensive Security Lead

Authentic8

Remote

$104K - $138K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 15 days ago


Job description

At some point in any digital investigation, an analyst needs to step beyond the perimeter and engage threats at the source.  Authentic8 Silo places any type of digital analyst in region-specific, multi-application workspaces, securely and anonymously, anywhere across the globe.  Target content can be captured, analyzed, and transformed in order to derive intelligence and support investigation requirements.  All delivered in a cloud-native, multi-tenant platform.

Compliance officers, mission managers, and administrators have their own specific audit and oversight requirements; to meet these needs, Silo also ensures compliance and appropriate use through class-leading policy enforcement and audit logging.  

Silo transforms how more than 750 of the world's most sophisticated organizations, from domestic and foreign government agencies to commercial entities across all sectors conduct their digital investigations.



Authentic8 is building an AI-powered Red Teaming Harness to proactively discover, chain, and validate vulnerabilities across our SaaS platform and supporting infrastructure. We are looking for a Red Team Engineer / Offensive Security Lead to drive the development and operation of that harness from the ground up. 

This is a hands-on role. You will be the primary builder and operator of the harness, working directly with our DevSecOps engineers, SOC Lead, and Director of Security Operations. You will conduct red team operations from multiple attack perspectives and feed validated, prioritized findings into our expedited patch management pipeline. You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program.

If you've spent years thinking like an adversary and you're energized by what frontier AI models can do in an offensive security context, this role was made for you.
Responsibilities:
Harness Development Responsibilities
 
  • Design, build, and operate an AI-augmented red teaming harness using frontier LLM APIs.
  • Implement a control loop architecture (Plan | Act | Observe | Adjust) for autonomous and semi-autonomous vulnerability discovery.
  • Integrate the harness with purpose-built SBOM tooling (Endor Labs), CVE monitoring feeds (NVD, OSV.dev, EPSS/KEV, GitHub Advisory Database, and vendor-specific bulletins), and our CI/CD pipeline (Snyk, SonarQube).
 
Red Team Operations Responsibilities
 
  • Conduct adversarial testing across four attack perspectives: (Internal source code, External unauthenticated adversary,  Internal authenticated user, and Internal unprivileged adversary)
  • Chain findings identify exploitable paths and corresponding vulnerabilities.
  • Validate and prioritize findings using CVSS, EPSS, and KEV context before handing off to the patch management pipeline.
  • Support the development and day-to-day operation of Authentic8's internal Bug Bounty Program.
  • Collaborate with engineering on custom mitigation decisions when vendor patches are unavailable.
 
SDLC & Collaboration Responsibilities
 
  • Assume ownership of security stage-gates within our CI/CD pipeline, integrating Snyk, SonarQube, and harness findings into the build process.
  • Work alongside the SOC Lead on CVE monitoring, alerting, and vulnerability prioritization workflows.
  • Partner with DevSecOps Engineers on harness architecture and pipeline integration.
  • Provide technical input to the Integrated Operations Center on detection use case design for our SIEM.
  • Regularly brief the VP of Information Security on findings, program health, and checkpoint criteria.
Qualifications:
  • 5+ years in cybersecurity, penetration testing, or red team operations
  • Demonstrated experience building tools: scripting exploits, automating workflows, or constructing test harnesses (Python and/or Go strongly preferred)
  • Hands-on experience with LLM APIs in a security or agent context, including an understanding of tool use, control loops, and context management in agent architectures
  • Proficiency with static and dynamic analysis (SAST/DAST) and the ability to interpret and chain findings from automated tooling
  • Working knowledge of CVE and vulnerability data sources, including NVD, EPSS, KEV, OSV.dev, and the GitHub Advisory Database
  • Experience testing cloud-hosted SaaS platforms (GCP familiarity preferred)
  • Familiarity with container security (containered, Docker) and Linux-based infrastructure
  • Ability to work independently, manage your own scope, and deliver against defined milestones
  • Excellent documentation and communication skills
  • Must be US citizen
Strongly Desired:
  • Experience with frontier AI model platforms in an agentic context
  • OSCP, GXPN, GPEN, or equivalent offensive security certification
  • Experience with SBOM tooling (Endor Labs, Syft, or similar) and software composition analysis
  • Familiarity with CI/CD pipeline security tooling (Snyk, SonarQube, or equivalents)
  • Experience with infrastructure-as-code or configuration management security (Chef/InSpec a plus)
  • Bug bounty program operations experience (HackerOne, Bugcrowd, or similar platforms)
Salary:
$150,000 - $175,000
Individual pay will be determined by location and additional factors, including job related skills, experience, and relevant education or training.
Authentic8 Core Values & Principles:

Integrity: We apply our best efforts. We are honest with and accountable to others.
Mission-Focused: We clearly define and communicate our goals and do not stray in the pursuit of our objective.
Respect: We value and respect the ideas and experience our diverse backgrounds bring us.  Positive consideration of differing viewpoints makes us stronger.
We are collaborative: We recognize the best work is the product of teams. We must each be reliable and expect to rely on others.
We are transparent:  By operating with common information and understanding we ensure that we are aligned.
We find innovative solutions:  We seek innovative solutions not as a buzzword but as a means to solve difficult problems with zeal, efficiency and quality.
We take ownership:  We are responsible for our actions, our reputation and our business. 

Authentic8 offers competitive benefits, including medical, dental and vision, flexible PTO, a 401k program and stock options.

It is the policy of Authentic8 to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. 
apply for this job