2

Remote Bug Bounty Program Jobs (NOW HIRING)

Familiarity with vulnerability scanning, penetration testing, and bug bounty/VDP program mechanics. * The "Builder" Edge: You are an active user of AI-native tools (Claude Code, Cursor, etc.) and ...

$45.25 - $60.50/hr

Investigate vulnerabilities reported through the bug bounty program, determine their root cause and ... Remote-first work: Join a fully distributed international team and work remotely. * Flexible ...

Product Security Engineering Manager

$170K - $177K/yr

... in Bug Bounty programs • A background in building 'paved roads' or secure-by-default internal libraries to eliminate entire classes of vulnerabilities • Experience working within a fast-paced ...

Coordinate with third-party security vendors for external assessments and bug bounty program management where applicable. Security Engineering * Own remediation follow-through: translate pen test ...

Coordinate with third-party security vendors for external assessments and bug bounty program management where applicable. Security Engineering * Own remediation follow-through: translate pen test ...

Experience with bug bounty programs and penetration testing * Security certifications such as CISSP ... There may be remote flexibility for exceptional candidates in the following states: California ...

Enterprise Account Executive

Chicago, IL · On-site +1

$116K - $160K/yr

Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions ... Environment - remote, work-from-home 100% of the time. Pay Range Disclosure At Bugcrowd, we strive ...

Product Security Engineer II

$60.25 - $80.25/hr

Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling ... Ability to write clear, maintainable scripts or small programs to solve practical problems ...

Product Security Engineer II

$60.25 - $80.25/hr

Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling ... S. states): $146,000 - $206,000 #LI-Remote

Have a background in QA automation, AppSec, API/security/pen testing, or bug bounty. * Have strong ... A track record in CTFs, red-team competitions, or responsible-disclosure / bounty programs. Why ...

You'll bring depth in security fundamentals and program design as a member of a small, high ... Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.

You'll bring depth in security fundamentals and program design as a member of a small, high ... Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands.

Showing results 41-60

Remote Bug Bounty Program information

See salary details

$16

$49

$78

How much do remote bug bounty program jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for remote bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is a remote bug bounty program?

Remote Bug Bounty Programs are initiatives run by organizations that invite independent security researchers, or 'bug hunters,' to find and report vulnerabilities in their software or systems. These programs are conducted entirely online, allowing participants from around the world to contribute remotely. Companies offer monetary rewards or other incentives for valid and impactful security findings. This approach helps organizations strengthen their security by leveraging a global pool of ethical hackers, while participants gain recognition and compensation for their expertise.

What skills and qualifications are needed to thrive in a remote bug bounty program?

To thrive in a Remote Bug Bounty Program role, you need a strong background in cybersecurity, vulnerability assessment, and ethical hacking, often supported by experience in penetration testing and security certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and various bug bounty platforms is essential. Attention to detail, persistence, effective communication, and self-motivation are standout soft skills for this position. These abilities are crucial for identifying and responsibly reporting security vulnerabilities that help organizations strengthen their defenses.

What are the biggest challenges faced by participants in a remote bug bounty program, and how can they be addressed?

One of the main challenges in remote bug bounty programs is staying motivated and disciplined without direct oversight, as participants often work independently. Additionally, understanding the specific security requirements and scope of each program can be complex, especially when dealing with varied platforms and reporting standards. To overcome these challenges, it's important to set personal goals, join online communities for peer support, and thoroughly review each program's documentation before starting. Effective communication with program coordinators can also help clarify expectations and facilitate successful submissions.

What is the difference between Remote Bug Bounty Program vs Remote Penetration Tester?

AspectRemote Bug Bounty ProgramRemote Penetration Tester
CredentialsTypically no formal certifications required, but cybersecurity knowledge helpsOften holds certifications like OSCP, CEH, or CISSP
Work EnvironmentParticipates remotely, often independently, on various platformsWorks remotely or on-site for clients, conducting security assessments
Employer & Industry UsageUsed by companies to crowdsource security testing; industry-wideEmployed by organizations or consulting firms to perform security audits

While both roles focus on cybersecurity, a Remote Bug Bounty Program involves independent testing on platforms to find vulnerabilities, whereas a Remote Penetration Tester conducts comprehensive security assessments for organizations, often with formal credentials and direct client engagement.

More about Remote Bug Bounty Program jobs

What cities are hiring for Remote Bug Bounty Program jobs?

Cities with the most Remote Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Remote Bug Bounty Program jobs?

States with the most job openings for Remote Bug Bounty Program jobs include:

What job categories do people searching Remote Bug Bounty Program jobs look for?

The top searched job categories for Remote Bug Bounty Program jobs are:

Infographic showing various Remote Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Staff Product Manager (AI & Data)

Bugcrowd

Remote

Full-time

Posted 29 days ago


Job description

Job Summary

We are looking for an innovative Staff Product Manager, AI & Data to define the vision, strategy, and roadmap for Bugcrowd's data and intelligence backbone. In this role, you will be the "Architect of the Signal," building the platform that turns a flood of raw test results, including vulnerability scans, penetration tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized intelligence customers can trust and act on. Your mission is to eliminate noise before it ever reaches a customer, connect the dots across every test type and source, and make sure the highest-risk issues, and the clearest path to fixing them, always rise to the top. You will sit at the intersection of data engineering, security operations, and applied AI/ML, owning the full lifecycle from raw test result to remediation guidance.

Essential Duties and Responsibilities

  • AI & Data Strategy & Vision: Own the vision, strategy, and roadmap for Bugcrowd's AI & Data pillar. Define how validation, aggregation, prioritization, and recommendations fit together into one trusted data platform.
  • Validation as a Service: Design and scale an automated triage and deduplication capability. It validates test results across all test types (vulnerability scanning, penetration testing, MBB/VDP) before they enter the data platform. Only clean, trustworthy signal reaches downstream products.
  • Aggregation & Correlation: Build the data models and pipelines that aggregate and correlate validated findings across test types and sources. The result is a single, unified view of a customer's risk posture.
  • Prioritization & Diagnosis: Develop the logic that diagnoses what matters most. Look within a customer across test results, across customers, and against third-party and internal threat feeds. The highest-impact issues should always surface first.
  • Recommendation Engine: Partner with engineering to turn a diagnosis into action. Surface a suggested code fix. Confirm whether the customer's logging can even detect the issue. Deliver a ready-to-use detection rule (e.g., Splunk) and a threat hunting query to check for past abuse.
  • Cross-Functional Intelligence: Work closely with our Agentic Products PM team. Feed new attack vectors and data sources back into agent training. Help our agents learn to "look for the new thing."
  • Platform Trust & Scalability: Define and own the metrics that prove the platform works: validation accuracy, deduplication rate, time-to-diagnosis. These metrics make the AI & Data pillar the trusted foundation every other product is built on.

Education, Experience, Knowledge, Skills, and Abilities

  • 7+ years of Product Management experience. Ideally this spans both security/vulnerability and threat data domains and ML/data platform and pipeline domains. That's a rare blend, but it's the ideal for this role.
  • Data-Minded Systems Thinker: You're comfortable with data models, pipelines, and deduplication/correlation logic. You can translate messy, multi-source data into a structured, trustworthy output.
  • Security Domain Fluency: You understand how different test types (vulnerability scanning, penetration testing, bug bounty/VDP) generate findings. You know what it takes to triage, validate, and prioritize them correctly.
  • Strategic Leader: You've been a contributor at the executive team level with the ability to build trust at every level and rally teams toward a long-term data strategy.
  • Tactical Execution: You balance the ambition of "one platform, one source of truth" with the pragmatic need to ship trustworthy improvements today.

Preferred Experience

  • Detection Engineering Familiarity: Exposure to writing or reviewing SIEM/Splunk-style detection rules and threat hunting queries.
  • ML/AI for Data Correlation: Experience building or product-managing systems that use ML for entity resolution, deduplication, anomaly detection, or risk scoring.
  • Security Testing Landscape: Familiarity with vulnerability scanning, penetration testing, and bug bounty/VDP program mechanics.
  • The "Builder" Edge: You are an active user of AI-native tools (Claude Code, Cursor, etc.) and likely have "robots" of your own running in your personal workflows.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Pay Range Disclosure

At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.

The national estimate for the current base range for the position is: $145,440 - $181,800.

This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.