2

Remote Bug Bounty Jobs (NOW HIRING)

Application Security Engineer- Remote

$60.25 - $80.25/hr

Application Security Engineer - Remote or Hybrid | Cary, North Carolina We're a leader in data and ... Triage security findings received through a public bug bounty program, communicating with both the ...

Customer Success Manager, MEA Remote Location: London, UK Position Summary At HackerOne, Customer ... Familiarity with bug bounty, vulnerability disclosure, penetration testing, or broader Job Benefits:

Bug bounty research experience #LI-Remote Instacart provides highly market-competitive compensation and benefits in each location where our employees work. This role is remote and the base pay range ...

Remote (West Coast - PST) Duration: 12-Month Contract Travel: None Compensation: $45-55/hr Note: A ... Support bug bounty programs by prioritizing and coordinating remediation efforts * Contribute to ...

Sr. Application Security Engineer

Charleston, WV ยท Remote

$60.25 - $80.25/hr

... moving, remote-first environment. Essential Functions and Responsibilities: * Lead security ... Own and operate the company's bug bounty program end-to-end: define program strategy and scope ...

Senior Security Engineer

New York, NY ยท On-site +1

$180K - $210K/yr

Triage vulnerability and bug-bounty findings by real exposure, drive remediation, and support ... Remote first - work from anywhere in the US & CAN! * Regular in-person company retreats and cross ...

Sr. Application Security Engineer

$60.25 - $80.25/hr

... moving, remote-first environment. Essential Functions and Responsibilities: * Lead security ... Own and operate the company's bug bounty program end-to-end: define program strategy and scope ...

$88K - $121K/yr

... or bug bounty programs is considered an advantage. Benefits * Competitive compensation package ... Fully remote work option for eligible candidates. * Flexible and collaborative international work ...

Remote (West Coast - PST) Duration: 12-Month Contract Travel: None Compensation: $45-55/hr Note: A ... Support bug bounty programs by prioritizing and coordinating remediation efforts * Contribute to ...

... remote assets. * Vulnerability management. Triage, prioritization, remediation tracking, and ... Experience standing up or running a vulnerability disclosure program or bug bounty, triage ...

Senior Security Engineer

New York, NY ยท Remote

$180K - $210K/yr

Triage vulnerability and bug-bounty findings by real exposure, drive remediation, and support ... Remote first - work from anywhere in the US & CAN! * Regular in-person company retreats and cross ...

Experience submitting to bug bounty programs or responsible disclosure programs Compensation The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend ...

Manage and coordinate external penetration testing and bug bounty programs focused on ACV ... Maintain strong communication channels with remote team members, ensuring alignment and fostering a ...

Senior Application Security Engineer

OR ยท Remote

$114K - $156K/yr

... remote environment. * Self-driven and proactive, comfortable operating in a high-autonomy ... Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ...

next page

Showing results 1-20

Remote Bug Bounty information

See salary details

$25

$30

$34

How much do remote bug bounty jobs pay per hour?

As of Jun 29, 2026, the average hourly pay for remote bug bounty in the United States is $30.69, according to ZipRecruiter salary data. Most workers in this role earn between $30.05 and $30.05 per hour, depending on experience, location, and employer.

What is the difference between Remote Bug Bounty vs Remote Penetration Tester?

AspectRemote Bug BountyRemote Penetration Tester
CredentialsKnowledge of security vulnerabilities, bug bounty platformsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentFreelance, project-based, remoteConsulting, in-house or remote, often more structured
Industry UsageTech companies, cybersecurity platforms, bug bounty programsSecurity firms, corporate security teams, consulting firms
Search & Comparison IntentFocus on finding vulnerabilities through bug bounty programsFocus on conducting comprehensive security assessments

Remote Bug Bounty roles involve identifying vulnerabilities via bug bounty platforms, often freelance and project-based. Remote Penetration Testers perform in-depth security assessments, usually with formal certifications and structured engagements. While both roles require cybersecurity knowledge, bug bounty work emphasizes finding bugs in live environments, whereas penetration testing involves simulated attacks to evaluate security posture.

What is a Remote Bug Bounty hunter?

A Remote Bug Bounty hunter is a cybersecurity professional who works from any location to find and report vulnerabilities in software, websites, or systems. They participate in bug bounty programs offered by companies or platforms, which reward individuals for responsibly disclosing security flaws. Remote Bug Bounty hunters use their skills to test for issues such as cross-site scripting, SQL injection, or authentication weaknesses. Their work helps organizations improve their security and protect user data, while also earning rewards or recognition for their discoveries.

What are the key skills and qualifications needed to thrive as a Remote Bug Bounty Hunter, and why are they important?

To thrive as a Remote Bug Bounty Hunter, you need a solid understanding of cybersecurity concepts, vulnerability assessment, and web application security, often supported by knowledge from certifications like CEH or OSCP. Familiarity with tools such as Burp Suite, Nmap, Metasploit, and automated scanning platforms is essential for identifying and reporting security flaws. Attention to detail, persistence, and strong written communication skills distinguish top performers in this field. These skills and qualities are crucial to effectively discovering, documenting, and responsibly disclosing vulnerabilities in diverse remote environments.

What are some common challenges remote bug bounty hunters face when working independently?

Remote bug bounty hunters often encounter challenges such as staying motivated without direct supervision, managing communication across different time zones with program managers, and keeping up with the latest security vulnerabilities and tools on their own. Additionally, prioritizing which programs to participate in and efficiently documenting findings for submission can be demanding. Building a professional network remotely and managing a healthy work-life balance are also important aspects to consider for long-term success.
More about Remote Bug Bounty jobs
What cities are hiring for Remote Bug Bounty jobs? Cities with the most Remote Bug Bounty job openings:
What are the most commonly searched types of Bug Bounty jobs? The most popular types of Bug Bounty jobs are:
What states have the most Remote Bug Bounty jobs? States with the most job openings for Remote Bug Bounty jobs include:
What job categories do people searching Remote Bug Bounty jobs look for? The top searched job categories for Remote Bug Bounty jobs are:

Security Engineer

Figma

San Francisco, CA โ€ข Remote

Other

Posted 7 days ago


Key responsibilities

  • Perform technical security assessments, code audits, and design reviews for Figma's products, platforms, and infrastructure.

  • Design and develop technical solutions to improve security and mitigate risks across Figma's AI, cloud, corporate, and product systems.

  • Participate in operational security activities such as vulnerability triage, penetration testing, security incident response, and consulting with other teams.


Job description

As a Security Engineer you will identify and drive impactful projects to improve the security of Figma's product, platform, and IT systems. We are hiring for multiple teams within Security Engineering: AI Security, Platform Security, Product Security, and Anti-Abuse. This is a remote first role.ย 

You will partner closely with teams across the company and focus on systemic security improvements and risk reduction. You will also participate in operational security responsibilities like security reviews, consulting, vulnerability triage, and security incident response.

Examples of what you may work on across teams:

AI Security

  • Perform technical security assessments, code audits, and design reviews for new AI infrastructure, platforms, and products.
  • Design and develop technical solutions to secure AI models, tooling, debugging workflows, and data pipelines.
  • Advocate for secure practices across Figma's AI infrastructure, platforms, and data systems.
  • Build the next generation of internal AI-powered access insights and security tooling.
  • Help run penetration testing and offensive security exercises against Figma's AI infrastructure, platforms, and products.

Platform Security

  • Perform technical security assessments, code audits, and design reviews for changes to Figma's cloud and corporate infrastructure.
  • Design and develop solutions to prevent or mitigate cloud and corporate security risks.
  • Advocate for secure practices within Figma's cloud and corporate infrastructure.
  • Build platforms and tooling to detect and respond to infrastructure and corporate security threats.

Product Security

  • Perform technical security assessments, code audits, and design reviews for new product features.
  • Design and develop solutions to prevent or mitigate product security vulnerabilities.
  • Advocate for secure development practices across Figma's products and services.
  • Help run penetration testing, offensive security exercises, and support our bug bounty program.
  • Help respond to product security incidents.

Anti-Abuse

  • Design and build technical systems to prevent spam, fraud, and abuse.
  • Partner closely with product teams to identify and address potential abuse vectors.
  • Develop new signals and improve the use of existing signals to detect abusive behavior.
  • Help respond to spam, fraud, and abuse incidents.

This is a full-time role that can be held from one of our US hubs or remotely in the United States.

We'd love to hear from you if you have:

  • 5+ years of proven engineering experience working in either a Security Engineering or a Software Engineering role. In the case of the latter, some security experience is preferred.
  • Strong security judgment in threat modeling and risk prioritization and/or strong technical judgment in designing and building maintainable, scalable systems.
  • Proficiency in at least one general-purpose coding language.
  • Strong communication and interpersonal skills, with demonstrated experience collaborating across functions.
While not required, it's an added plus if you also have:
  • Subject matter expertise in Application Security, Cloud Security, Corporate Security, Data Access Governance, and/or IAM (Identity and Access Management).
  • Demonstrated ability to make hard prioritization decisions in security controls.

At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you're excited about this role but your past experience doesn't align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.

#LI-Remote