1

Top Bug Bounty Jobs (NOW HIRING)

Senior Security Engineer

Los Angeles, CA · On-site

$91K - $149K/yr

... Top 10 and common web/mobile application vulnerabilities. * Hands-on experience with web application vulnerability assessments and penetration testing. * Familiarity with bug bounty platforms (e.g ...

Senior Security Engineer

Los Angeles, CA · On-site

$123K - $169K/yr

... Top 10 and common web/mobile application vulnerabilities. * Hands-on experience with web application vulnerability assessments and penetration testing. * Familiarity with bug bounty platforms (e.g ...

Triage and validate reports from automated scanners or bug bounty hunters to eliminate false ... Expert Knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web ...

Triage and validate reports from automated scanners or bug bounty hunters to eliminate false ... Expert Knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web ...

Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the ... Bug Bounty Triage: Perform the technical triage and validation of Cloudflare's external Bug Bounty ...

Strong knowledge of OWASP Top 10 , SANS 25 , and NIST standards * Hands-on with secure coding reviews and CICD DevSecOps integration * Experience in Red Teaming and bug bounty programs preferred ...

... tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized ... top. You will sit at the intersection of data engineering, security operations, and applied AI/ML ...

... top. You will sit at the intersection of data engineering, security operations, and applied AI/ML ... You understand how different test types (vulnerability scanning, penetration testing, bug bounty ...

NY · On-site

$120 - $150/hr

Triage vulnerabilities from the bug bounty program, collaborating with external researchers and ... Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical ...

$180 - $250/hr

... Bug bounty Attack-surface management Threat intelligence Artificial Intelligence and Machine Learning applications OWASP Top 10 Skills Application Security Secure Software Development Lifecycle ...

next page

Showing results 1-20

Top Bug Bounty information

What cities are hiring for Top Bug Bounty jobs?

Cities with the most Top Bug Bounty job openings:

What states have the most Top Bug Bounty jobs?

States with the most job openings for Top Bug Bounty jobs include:

What job categories do people searching Top Bug Bounty jobs look for?

The top searched job categories for Top Bug Bounty jobs are:

Infographic showing various Top Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 19% Part Time, and 8% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Product Security Engineer (PSIRT - Product Security Incident Response Team)

Replit

Foster City, CA • On-site

$180K - $325K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 18 days ago


Key responsibilities

  • Manage the lifecycle of security vulnerabilities affecting Replit's products and services, from intake to validation, remediation coordination, and public disclosure.

  • Validate, reproduce, and document security findings; assess relevance and exploitability; and maintain vulnerability records.

  • Coordinate with engineering, security, and operations teams to confirm impact, drive remediation, and track progress.


Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit's cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services-from intake to validation, remediation coordination, and public disclosure.
This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly.
What You'll Do
Vulnerability Intake, Triage & Validation
  • Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
  • Independently validate, reproduce, severity-score, and document findings.
  • Identify duplicates and maintain a clean vulnerability records pipeline.
  • Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
Remediation Coordination & SLA Management
  • Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
  • Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
  • Track SLAs, remediation progress, regression testing, and systemic improvements.
  • Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
Bug Bounty & Vulnerability Disclosure Program Management
  • Design and evolve the bug bounty program, including scope, rules, and reward structures.
  • Manage platform selection, private vs. public launches, and community engagement.
  • Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
  • Determine reward payouts, bonus decisions, and recognition for top contributors.
Coordinated Disclosure & CVE Management
  • Lead the coordinated vulnerability disclosure process for internal and external findings.
  • Negotiate disclosure timelines with researchers and partners.
  • Coordinate CVE assignments and publications, and prepare customer/public advisories.

Required Skills
  • Experience running or triaging for bug bounty programs (HackerOne ideally).
  • Strong ability to triage, validate, and reproduce vulnerabilities independently.
  • Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
  • Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
  • Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.

Nice to Have
  • Scripting or automation experience (Python, Go, Bash).
  • Pentesting background or exposure to offensive security work.
  • Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
  • Experience authoring public advisories or CVE writeups.
  • Hands-on experience with SIEM, Cloud Logging, and investigative tooling.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
Competitive Salary & Equity
401(k) Program with a 4% match (US Only)
Health, Dental, Vision and Life Insurance
Short Term and Long Term Disability
Paid Parental, Medical, Caregiver Leave
Flexible Time Off (FTO) + Holidays
Commuter Benefits (In-Office & US Only)
Monthly Wellness Stipend
Autonomous Work Environment
In Office Set-Up Reimbursement (In-Office Only)
Quarterly Team Gatherings
In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Self-driving Company
  • Replit Agent at Scale
  • AI Adoption
  • Build Open-Source Apps

Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.