Track record of successful bug bounty contributions Desired/Nice to Have * Experience developing ... Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and ...
Track record of successful bug bounty contributions Desired/Nice to Have * Experience developing ... Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and ...
Gen AI Security & DevSecOps Engineer
Secaucus, NJ · On-site +1
Remote Position Summary: As a Senior Manager in League Office CyberSecurity department, the Gen AI ... bug bounty findings. * Design and build the enterprise security operations platform and the ...
Gen AI Security & DevSecOps Engineer
Secaucus, NJ · On-site +1
Remote Position Summary: As a Senior Manager in League Office CyberSecurity department, the Gen AI ... bug bounty findings. * Design and build the enterprise security operations platform and the ...
Application Security Engineer
Long Beach, CA · On-site +1
Remote work from home on Mondays and Fridays. About the Role - Key Responsibilities: * Assist in ... Monitor and triage security findings from scanners, bug bounty programs, or internal testing
Quick apply
Application Security Engineer
Long Beach, CA · On-site +1
Remote work from home on Mondays and Fridays. About the Role - Key Responsibilities: * Assist in ... Monitor and triage security findings from scanners, bug bounty programs, or internal testing
Limited Cyberspace Operator
Annapolis, MD · On-site +1
$69K - $158K/yr
... commercial bug bounty programs * Experience with databases, backend systems, and supporting ... Remote : If this position is listed as remote, there may still be occasions when you are required ...
Limited Cyberspace Operator
Annapolis, MD · On-site +1
$69K - $158K/yr
... commercial bug bounty programs * Experience with databases, backend systems, and supporting ... Remote : If this position is listed as remote, there may still be occasions when you are required ...
Sr. Security Engineer (Penetration Testing)
OR · Remote
$100K - $180K/yr
Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...
Quick apply
Sr. Security Engineer (Penetration Testing)
OR · Remote
$100K - $180K/yr
Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...
Staff Product Security Engineer
Charleston, WV · On-site +1
Location is remote with the ability to work from anywhere within the continental United States. Key ... Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty ...
Staff Product Security Engineer
Charleston, WV · On-site +1
Location is remote with the ability to work from anywhere within the continental United States. Key ... Triage, coordinate, and oversee remediation for security researcher disclosures via our bug bounty ...
Principal Application Security Engineer
$177K - $225K/yr
This role can be fully remote and must reside in US. In this role, you will help us drive our ... Drive our security assessment, penetration testing and bug bounty programs * Participate in ...
Principal Application Security Engineer
$177K - $225K/yr
This role can be fully remote and must reside in US. In this role, you will help us drive our ... Drive our security assessment, penetration testing and bug bounty programs * Participate in ...
Remote _____ Position Summary: As a Senior Manager in League Office CyberSecurity department, the ... bug bounty findings. * Design and build the enterprise security operations platform and the ...
Remote _____ Position Summary: As a Senior Manager in League Office CyberSecurity department, the ... bug bounty findings. * Design and build the enterprise security operations platform and the ...
Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ... fun, remote-friendly, start-up environment-apply anyway, detailing your relevant transferable ...
Determine the root cause and severity of vulnerabilities reported to us through our bug bounty ... fun, remote-friendly, start-up environment-apply anyway, detailing your relevant transferable ...
Senior Security Engineer
Burlington, VT · Remote
Remote-Friendly About the Role: We're looking for a Senior Security Engineer to lead application ... Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen ...
Quick apply
Senior Security Engineer
Burlington, VT · Remote
Remote-Friendly About the Role: We're looking for a Senior Security Engineer to lead application ... Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen ...
Application Security Engineer
Long Beach, CA · On-site +1
$108K - $140K/yr
Remote work from home on Mondays and Fridays. About the Role - Key Responsibilities: * Assist in ... Monitor and triage security findings from scanners, bug bounty programs, or internal testing
Application Security Engineer
Long Beach, CA · On-site +1
$108K - $140K/yr
Remote work from home on Mondays and Fridays. About the Role - Key Responsibilities: * Assist in ... Monitor and triage security findings from scanners, bug bounty programs, or internal testing
Senior Application Security Engineer
$180K - $225K/yr
Triage Bug Bounty findings and responsibility disclosed vulnerabilities. * Able to participate in ... Remote.com. Additionally, Temporal offers perks to all international employees for learning ...
Senior Application Security Engineer
$180K - $225K/yr
Triage Bug Bounty findings and responsibility disclosed vulnerabilities. * Able to participate in ... Remote.com. Additionally, Temporal offers perks to all international employees for learning ...
Sr. Security Engineer (Penetration Testing)
$100K - $180K/yr
Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...
Sr. Security Engineer (Penetration Testing)
$100K - $180K/yr
Participated in bug bounty programs and audit contests * Published security-related blog posts and ... LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental ...
Staff Product Security Engineer
$217K - $303K/yr
Experience with vulnerability discovery and remediation pipelines, including bug bounty or ... them. #LI-Remote Pay Transparency: This job posting may span more than one career level. In ...
Staff Product Security Engineer
$217K - $303K/yr
Experience with vulnerability discovery and remediation pipelines, including bug bounty or ... them. #LI-Remote Pay Transparency: This job posting may span more than one career level. In ...
Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep ... Remote work with regular in-person bonding experiences sponsored by the company * Competitive ...
Strong background in offensive security (red team, penetration testing, or bug bounty) * Deep ... Remote work with regular in-person bonding experiences sponsored by the company * Competitive ...
Senior Product Security Engineer
$157K - $184K/yr
Background in security research or offensive security (bug bounty, CTF, penetration testing). Base ... Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual ...
Senior Product Security Engineer
$157K - $184K/yr
Background in security research or offensive security (bug bounty, CTF, penetration testing). Base ... Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual ...
Remote Bug Bounty information
See salary details
$25 - $25.83
0% of jobs
$25.83 - $26.66
0% of jobs
$26.66 - $27.49
0% of jobs
$27.49 - $28.32
0% of jobs
$28.32 - $29.15
0% of jobs
$29.15 - $29.98
18% of jobs
$30.06 is the 25th percentile. Wages below this are outliers.
$29.98 - $30.81
71% of jobs
$30.81 - $31.64
3% of jobs
$31.64 - $32.47
2% of jobs
$32.47 - $33.30
3% of jobs
$33.30 - $34.13
2% of jobs
$25
$30
$34
How much do remote bug bounty jobs pay per hour?
What is the difference between Remote Bug Bounty vs Remote Penetration Tester?
| Aspect | Remote Bug Bounty | Remote Penetration Tester |
|---|---|---|
| Credentials | Knowledge of security vulnerabilities, bug bounty platforms | Certifications like OSCP, CEH, CISSP often preferred |
| Work Environment | Freelance, project-based, remote | Consulting, in-house or remote, often more structured |
| Industry Usage | Tech companies, cybersecurity platforms, bug bounty programs | Security firms, corporate security teams, consulting firms |
| Search & Comparison Intent | Focus on finding vulnerabilities through bug bounty programs | Focus on conducting comprehensive security assessments |
Remote Bug Bounty roles involve identifying vulnerabilities via bug bounty platforms, often freelance and project-based. Remote Penetration Testers perform in-depth security assessments, usually with formal certifications and structured engagements. While both roles require cybersecurity knowledge, bug bounty work emphasizes finding bugs in live environments, whereas penetration testing involves simulated attacks to evaluate security posture.
What is a Remote Bug Bounty hunter?
What are the key skills and qualifications needed to thrive as a Remote Bug Bounty Hunter, and why are they important?
What are some common challenges remote bug bounty hunters face when working independently?

Full-time
Medical, Dental, Vision, PTO
Re-posted 8 days ago
Job description
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.
We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox" security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.
Summary
We're looking for a Senior/ Staff Offensive Security Software Engineer with extensive web application penetration testing experience and a growing interest in AI-enhanced security techniques. You will have a significant impact on how we deliver value to our customers by designing, developing, and integrating web application penetration testing content into the NodeZero platform. This position requires practical expertise in full-scope web application testing, proven software development skills, and enthusiasm for leveraging emerging AI technologies to advance offensive security capabilities.
Essential Functions
- Perform hands-on, full-scope web application penetration tests against real customer applications, alongside benchmark and lab targets, to surface vulnerabilities and attack paths.
- Review NodeZero results on live customer engagements to identify coverage gaps, blind spots, and missed opportunities - the edge cases and corner-case attack scenarios that autonomous testing doesn't yet handle.
- Manually reproduce and validate those edge cases, building reliable, production-safe proof-of-concept exploits and clear test cases that demonstrate the gap end to end - including against live customer environments without disrupting them.
- Partner closely with software engineers to translate your findings into product improvements - defining detection logic, attack content, expected behavior, and remediation so NodeZero handles those cases going forward.
- Build and maintain a library of regression and benchmark test cases so newly added coverage doesn't silently regress over time.
- Monitor production pentests for missed findings and false positives; create and triage Jira tickets to drive issues to resolution.
- Work directly with customers and internal teams to investigate findings, explain attack paths, and address questions about web application coverage and results.
- Author technical blog posts and research write-ups showcasing new exploits, edge cases, and attack methodologies.
- Mentor teammates and contribute to continuous improvement of team processes, methodology, and testing standards.
Competencies/Requirements
- Experience conducting full scope web application pentests
- Experience with proxy tools like Burp and with browser developer tools
- Proficient in object-oriented programming and test-driven development, with strong analytical and problem-solving skills.
- Experience applying AI-assisted development tools to security research and automation tasks
- Curiosity about emerging AI technologies.
- Skilled in designing, evaluating, and communicating technical solutions across systems, APIs, algorithms, and data structures.
- Familiarity with relational and graph databases, particularly Postgres and Neo4j.
- Strong written and verbal communication, including technical documentation.
- Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels.
- Quick to learn and adopt new technologies as needed.
- History of recognized security research, including documented CVE discoveries and responsible disclosure
- Track record of successful bug bounty contributions
Desired/Nice to Have
- Experience developing software and automation to aid in web application pentesting
- Background in large-scale software development projects.
- Experience fine-tuning language models or implementing retrieval-augmented generation (RAG) for security-focused applications.
- Experience with AI/LLM tools for building agentic workflows (e.g., LangChain, LangFlow) and integrating contextual data using protocols like Model Context Protocol (MCP).
Expectations:
- Outstanding problem-solving aptitude.
- Be self-motivated and highly energetic to have the ability to operate effectively with limited supervision and guidance.
- Work with our security researchers to understand the technical aspects of reverse engineered exploits and weaponizing these exploits into the product.
- Strong technical documentation and communication skills.
- Document findings, methodologies, and recommendations for both technical and non-technical stakeholders.
- Proficient in designing, presenting, and evaluating technical solutions.
What makes you stand out:
- Demonstrated examples of using AI to enhance or automate exploit development
- OSCP (Offensive Security Certified Professional) Certification.
Perks of Horizon3.ai
- Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
- Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
- Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
- Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.
- Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.
Compensation and Values
At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.
In accordance with various State's transparency regulations, we provide the following salary range information for this position:
- Base salary range: $196,000 - $242,000. The exact salary will be determined based on the selected candidate's location, qualifications, experience, and relevant skills.
- Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.
You Belong Here
Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law.
Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.
We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
About Horizon3.ai
Sourced by ZipRecruiter
Industry
Network security
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US
Year founded
2019