2

Remote Bug Bounty Jobs (NOW HIRING)

Sr. Application Security Engineer

Charleston, WV ยท Remote

$60.25 - $80.25/hr

... moving, remote-first environment. Essential Functions and Responsibilities: * Lead security ... Own and operate the company's bug bounty program end-to-end: define program strategy and scope ...

Security Engineer

$140K - $190K/yr

In addition, they are the key points of contact for audit engagements and bug bounty reports. We ... Our team is remote first and we are hiring across the world. Here at Mysten Labs, you'll be joining ...

Remote (West Coast - PST) Duration: 12-Month Contract Travel: None Compensation: $45-55/hr Note: A ... Support bug bounty programs by prioritizing and coordinating remediation efforts * Contribute to ...

... remote assets. * Vulnerability management. Triage, prioritization, remediation tracking, and ... Experience standing up or running a vulnerability disclosure program or bug bounty, triage ...

Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog ... We offer parental leave, paid-time off and fully remote working arrangements. Benefits include ...

Sr. Security Engineer (Penetration Testing)

OR ยท Remote

$100K - $180K/yr

Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...

Manage and coordinate external penetration testing and bug bounty programs focused on ACV ... Maintain strong communication channels with remote team members, ensuring alignment and fostering a ...

Manage and coordinate external penetration testing and bug bounty programs focused on ACV ... Maintain strong communication channels with remote team members, ensuring alignment and fostering a ...

Technical Program Manager - Security

Seattle, WA ยท On-site +1

$130K - $170K/yr

We are open to remote. Your Daily Adventures Will Include: * Drive security vulnerability ... Bug Bounty Program > * Familiar with security tooling and system integrations > * Experience ...

Senior Application Security Engineer

OR ยท Remote

$114K - $156K/yr

... remote environment. * Self-driven and proactive, comfortable operating in a high-autonomy ... Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ...

This is a remote first role. You will partner closely with teams across the company and focus on ... Help run penetration testing, offensive security exercises, and support our bug bounty program.

Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...

Application Security Engineer

$60.25 - $80.25/hr

Take part in our security assessment, penetration testing and bug bounty programs * Participate in ... Ability to work extended hours as required #LI-JC1 #LI-REMOTE The anticipated pay scale for this ...

Manage and coordinate external penetration testing and bug bounty programs focused on ACV ... Maintain strong communication channels with remote team members, ensuring alignment and fostering a ...

This role can be fully remote and must reside in US. In this role, you will help us drive our ... Drive our security assessment, penetration testing and bug bounty programs * Participate in ...

Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ... fun, remote-friendly, start-up environment-apply anyway, detailing your relevant transferable ...

next page

Showing results 1-20

Remote Bug Bounty information

See salary details

$25

$30

$34

How much do remote bug bounty jobs pay per hour?

As of Jun 8, 2026, the average hourly pay for remote bug bounty in the United States is $30.69, according to ZipRecruiter salary data. Most workers in this role earn between $30.05 and $30.05 per hour, depending on experience, location, and employer.

What is the difference between Remote Bug Bounty vs Remote Penetration Tester?

AspectRemote Bug BountyRemote Penetration Tester
CredentialsKnowledge of security vulnerabilities, bug bounty platformsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentFreelance, project-based, remoteConsulting, in-house or remote, often more structured
Industry UsageTech companies, cybersecurity platforms, bug bounty programsSecurity firms, corporate security teams, consulting firms
Search & Comparison IntentFocus on finding vulnerabilities through bug bounty programsFocus on conducting comprehensive security assessments

Remote Bug Bounty roles involve identifying vulnerabilities via bug bounty platforms, often freelance and project-based. Remote Penetration Testers perform in-depth security assessments, usually with formal certifications and structured engagements. While both roles require cybersecurity knowledge, bug bounty work emphasizes finding bugs in live environments, whereas penetration testing involves simulated attacks to evaluate security posture.

What is a Remote Bug Bounty hunter?

A Remote Bug Bounty hunter is a cybersecurity professional who works from any location to find and report vulnerabilities in software, websites, or systems. They participate in bug bounty programs offered by companies or platforms, which reward individuals for responsibly disclosing security flaws. Remote Bug Bounty hunters use their skills to test for issues such as cross-site scripting, SQL injection, or authentication weaknesses. Their work helps organizations improve their security and protect user data, while also earning rewards or recognition for their discoveries.

What are the key skills and qualifications needed to thrive as a Remote Bug Bounty Hunter, and why are they important?

To thrive as a Remote Bug Bounty Hunter, you need a solid understanding of cybersecurity concepts, vulnerability assessment, and web application security, often supported by knowledge from certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and automated scanning platforms is essential for identifying and reporting security flaws. Attention to detail, persistence, and strong written communication skills distinguish top performers in this field. These skills and qualities are crucial to effectively discovering, documenting, and responsibly disclosing vulnerabilities in diverse remote environments.

What are some common challenges remote bug bounty hunters face when working independently?

Remote bug bounty hunters often encounter challenges such as staying motivated without direct supervision, managing communication across different time zones with program managers, and keeping up with the latest security vulnerabilities and tools on their own. Additionally, prioritizing which programs to participate in and efficiently documenting findings for submission can be demanding. Building a professional network remotely and managing a healthy work-life balance are also important aspects to consider for long-term success.
More about Remote Bug Bounty jobs
What cities are hiring for Remote Bug Bounty jobs? Cities with the most Remote Bug Bounty job openings:
What are the most commonly searched types of Bug Bounty jobs? The most popular types of Bug Bounty jobs are:
What states have the most Remote Bug Bounty jobs? States with the most job openings for Remote Bug Bounty jobs include:
Infographic showing various Remote Bug Bounty job openings in the United States as of May 2026, with employment types broken down into 80% Full Time, 14% Temporary, and 6% Nights. Highlights an 79% Physical, 4% Hybrid, and 17% Remote job distribution, with an average salary of $63,838 per year, or $30.7 per hour.
Sr. Application Security Engineer

Sr. Application Security Engineer

Lumin Digital

Charleston, WV โ€ข Remote

$60.25 - $80.25/hr

Full-time

Posted 11 days ago


Job description

Basic Function

The Senior Application Security Engineer is a hands-on technical leader responsible for securing Lumin Digitalโ€™s B2B2C SaaS platform across the full software development lifecycle. This role exists at the intersection of application security and AI-augmented engineering: the ideal candidate actively uses AI-powered tools such as Claude Code and Claude Security in their daily workflow to find vulnerabilities faster, automate remediation, and scale security coverage beyond what traditional approaches allow. As AI rapidly transforms how code is written, reviewed, and deployed, this engineer will lead the effort to secure AI-integrated applications, harden CI/CD pipelines, and establish governance for responsible AI adoption across product and engineering teams. Success in this role requires deep technical fluency, a bias toward building and doing over advising, and the ability to operate independently in a fast-moving, remote-first environment.

Essential Functions and Responsibilities:

  • Lead security architecture reviews for new and existing applications, ensuring secure-by-design principles are embedded from initial design through deployment and ongoing operation.

  • Develop, enforce, and continuously refine secure coding standards across engineering teams through a combination of automated security scans (SAST, DAST, SCA), AI-assisted code review using tools such as Claude Code, periodic manual code audits, and targeted secure development training.

  • Own the design, implementation, and evolution of Application Security Posture Management (ASPM) capabilities, integrating signals from static analysis, dynamic testing, software composition analysis, and runtime telemetry to build risk-scoring models that balance exploitability, data sensitivity, and business impact.

  • Continuously improve threat modeling frameworks across application components, third-party integrations, cloud-native architectures, and AI/LLM-powered features, leveraging tools such as Claude Security for accelerated threat model generation and scenario analysis.

  • Develop custom security automation tools and scripts to improve detection and response capabilities across cloud environments, including AI-assisted vulnerability auto-fix workflows and integration of AI-powered security tooling into CI/CD pipelines.

  • Own and operate the companyโ€™s bug bounty program end-to-end: define program strategy and scope, triage and validate external researcher submissions, assess severity, and maintain productive engagement with the security research community.

  • Manage vulnerability triage and prioritization processes, ensuring vulnerabilities are assessed based on exploitability, business impact, and compliance requirements, and that remediation timelines align with organizational risk tolerance.

  • Influence product roadmaps by identifying and advocating for security enhancements aligned with evolving regulatory requirements, industry best practices, and the emerging threat landscape for AI-integrated applications.

  • Mentor security engineers and developers through hands-on guidance in secure coding, vulnerability remediation, and effective use of AI-augmented security workflows.

  • Present security findings, risk assessments, and program metrics to senior leadership, clients, auditors, and regulators in a clear, actionable manner.

  • Perform other duties as assigned.

Physical Demands:

  • While performing the duties of this job, the employee is regularly required to sit; use hands to type, handle, or feel and talk or hear.

  • Specific vision abilities required by this job include close vision.

  • Ability to occasionally lift/move up to 25 pounds.

  • Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.

Supervisory Responsibility:

None

Position Specifications

Education:

  • Bachelorโ€™s in Computer Science, Cybersecurity, Information Assurance, Software Engineering, or a related field, or an equivalent combination of education and experience.

  • Preferred certifications: CSSLP, OSCP, GWEB, or GWAPT.

Experience:

  • Seven (7+) years of progressive experience in application security, software security engineering, or a closely related domain within production SaaS environments.

  • Extensive hands-on experience in secure software development, DevSecOps pipeline design, and security testing methodologies (SAST, DAST, SCA, penetration testing).

  • Demonstrated experience securing large-scale cloud-native applications, APIs, and microservices architectures.

  • Experience leading application security initiatives, defining program strategy, and mentoring engineering teams on secure development practices.

  • Demonstrated, regular hands-on use of AI-powered security and development tools (e.g., Claude Code, Claude Security, or comparable coding/security assistants) as part of daily security engineering workflows, not solely in an evaluative, advisory, or training capacity.

  • Experience assessing AI-specific attack surfaces in LLM-integrated applications, including prompt injection, context leakage, insecure tool use, and model denial-of-service.

Knowledge, Skills, & Abilities:

Required:

  • Deep expertise in AWS security, Kubernetes security, and cloud-native application security best practices.

  • Strong programming proficiency with the ability to review and assess security risks in one or more of: Java, C#, JavaScript/TypeScript, Python, Swift, or Kotlin.

  • Expertise in secure authentication and authorization mechanisms, including OAuth 2.0, OIDC, SAML, JWT, WebAuthn, and Zero Trust principles.

  • Hands-on proficiency with AI-augmented security workflows, including daily use of AI tools (e.g., Claude Code, Claude Security) for vulnerability discovery, remediation assistance, threat modeling, and security automation across the SDLC.

  • Strong understanding of OWASP Top 10, OWASP Top 10 for LLM Applications, SANS 25, CVSS/EPSS scoring, and MITRE ATT&CK framework.

  • Ability to identify, assess, and mitigate prompt injection vulnerabilities (direct and indirect) in LLM-integrated applications through input validation, output sanitization, instruction hierarchy enforcement, and adversarial prompt testing.

  • Experience with secure context window management in AI-powered products, including preventing sensitive data leakage, enforcing context isolation boundaries, and defining data classification policies for AI model inputs.

  • Hands-on experience with security automation and scripting (Python, Bash, or equivalent).

  • Proficiency in penetration testing methodologies, including automated and manual security testing of web applications, APIs, and mobile platforms.

  • Strong knowledge of encryption standards, cryptographic best practices, and secrets management.

  • Ability to communicate complex security concepts to both technical and non-technical audiences, and to present risk assessments to senior leadership and external stakeholders.

  • Demonstrated ability to work independently in a remote setting while maintaining high performance and accountability.

Preferred:

  • Experience evaluating the security posture of AI providers (API security reviews, data residency assessments, vendor risk questionnaires, and contractual security requirements).

  • Familiarity with AI model access controls and secrets hygiene in AI pipelines, including least-privilege principles for LLM tool integrations and securing model inference endpoints.

  • Experience with SIEM, WAF, and security monitoring tools.

  • Familiarity with cloud security controls in AWS, including IAM, security groups, KMS, Lambda security, and cloud monitoring.

  • Strong project management abilities and experience collaborating across product, engineering, and compliance teams.

Travel:

  • Minimal, generally 12 days or less per year, ~2X team get-togethers a year.

LIFE AT LUMIN DIGITAL

Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. We empower credit unions and banks by creating cutting-edge digital experiences that continuously serve, engage, and grow their membership base โ€” and as a 100% cloud-native company, we're purpose-built to unlock the full advantages of the cloud for financial institutions and their users.

At Lumin, we thrive on curiosity and innovation. Our culture is built on trust in our expertise and decisions, respect for diverse perspectives and talents, and boldness in pursuing new ideas. These values shape a workplace where collaboration thrives, ideas flourish, and new possibilities are discovered every day. We encourage our team to explore, experiment, and challenge the status quo โ€” because continuous improvement isn't just a goal, it's how we operate.

Benefits Include We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave. We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend. Additional details are provided during the interview process.

Lumin Digital is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis.

For more information, visitย lumindigital.com.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.