1

Top Bug Bounty Jobs (NOW HIRING)

Apply and promote secure coding standards aligned to OWASP and SANS CWE Top 25, and contribute to ... Driving additional Bug Bounty submissions and improve bot management turning & protections prior to ...

NY · On-site

$140 - $200/hr

We bake challenges by using agile methodologies, top line tools and of course always working with ... Scale and enhance SSDLC and bug bounty programs to align with the needs of a rapidly growing ...

New

$106K - $145K/yr

... bug bounty. Drive findings to closure and feed recurring issues back into preventive controls ... Germany\'s top financial platforms for SMEs and private accounts. Since then, we\'ve expanded ...

Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team's work demands ... OWASP Top 10, authentication and authorization patterns, secrets management, and common cloud ...

OR

$180K - $225K/yr

OWASP Top 10 for LLMs, MCP security specifications) and translate these into actionable internal policy. * Triage Bug Bounty findings and responsibility disclosed vulnerabilities. * Able to ...

AI Red Team Engineer

$60K - $90K/yr

We've raised $11M from top funds, founders, and senior leaders at OpenAI, Anthropic, HuggingFace ... Have a background in QA automation, AppSec, API/security/pen testing, or bug bounty. * Have strong ...

... Top 10, injection, auth flaws, insecure deserialization, etc.) • Drive vulnerability ... operate our bug bounty program end to end: triage, response, remediation, and researcher ...

Principal Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

Drive our security assessment, penetration testing and bug bounty programs * Participate in ... at a top-tier software company including experience with security products, threat modeling ...

Senior AI Engineer

New York, NY · Remote

$150K - $220K/yr

Offensive security certifications or experience (OSCP/OSWE/OSWA, CTF, bug bounty, red team) * Research publications at top ML/security venues or open source contributions to agent/LLM tooling

Strong web application and API testing fundamentals - Burp Suite proficiency, OWASP Top 10 and ... Active involvement in cybersecurity communities, research, or bug bounty programs * Certifications ...

Co-founder and CEO Jack Cable is a top-ranked bug bounty hunter who previously led Secure by Design at CISA. * Co-founder and CTO Ashwin Ramaswami built large-scale systems at Skiff, Caldera, and ...

Application Security Engineer

Phoenix, AZ

$58.25 - $78/hr

Strong knowledge of OWASP Top 10, OWASP API Top 10, and modern authentication mechanisms, including ... Experience managing or supporting vulnerability disclosure or bug bounty programs. * Strong written ...

... bug bounty program, including triage, response processes, and improvements to vulnerability ... OWASP Top 10, MITRE ATT&CK, etc.) • Strong software engineering background with experience ...

Sr/Staff Security Engineer

$117K - $160K/yr

Conduct or coordinate penetration tests, red team exercises, and bug bounty triage; drive ... Strong understanding of secure software development practices - OWASP Top 10, threat modeling ...

AppSec Engineer

Santa Clara, CA · Remote

$80K - $100K/yr

Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns ... Bug bounty experience, public CVEs, or open-source security contributions. * Familiarity with AI ...

Showing results 21-40

Top Bug Bounty information

What cities are hiring for Top Bug Bounty jobs? Cities with the most Top Bug Bounty job openings:
What states have the most Top Bug Bounty jobs? States with the most job openings for Top Bug Bounty jobs include:
What job categories do people searching Top Bug Bounty jobs look for? The top searched job categories for Top Bug Bounty jobs are:
Infographic showing various Top Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 17% Part Time, and 8% Contract. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution.

Software Security Engineer

Wolfe, LLC

Pittsburgh, PA

$110K - $120K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 7 days ago


Job description

Description
About The Role
Wolfe is a Pittsburgh-based FinTech company building the next generation of financial products, and we are actively embedding AI across our product, our internal processes, and the way our teams work day-to-day. As a Software/Application Security Engineer, you'll work hands-on alongside developers and DevOps engineers to build security into how we ship software — reviewing code, harden the AI agents, MCP integrations, and LLM-backed features we're actively shipping, hardening CI/CD pipelines, and helping teams find and fix vulnerabilities across application code, containers, and cloud infrastructure. 
 
This role is built for a developer. Whether you're a software engineer moving into security or an early-career security engineer expanding into AppSec, you'll work hands-on alongside developers and DevOps engineers and learn enterprise security tooling — including secure code development AI/ML and LLM-powered tools — with support to earn certifications and grow alongside a security team that mentors in person.  You'll be working alongside developers using languages such as TypeScript/Node, Deno, Bun, Dart, Next.js, php, react, and Python codebases, plus Terraform/Ansible and containerized services on AWS. 
We're looking for candidates who are enthusiastic about an in-office culture. This is a 5-day onsite role in Pittsburgh, PA.  

Responsibilities
  • Perform code reviews, SAST/DAST testing, penetration tests, and threat modeling, and work with developers to remediate vulnerabilities across application code, libraries, containers, and infrastructure as code.  
  • Integrate and run automated security tooling (such as Snyk, SemGrep, or Cycode) within CI/CD pipelines across code repositories (such as GitHub, GitLab, Jenkins, or AWS DevOps), and automate findings triage and reporting.  
  • Build the automation that triages, routes, and reports vulnerability findings, and run our enterprise Bug Bounty program. 
  • Operate and improve Bot Management, WAF, secrets management, and API security controls across Wolfe's applications.  
  • Apply and promote secure coding standards aligned to OWASP and SANS CWE Top 25, and contribute to measuring DevSecOps maturity using a framework such as DSOMM or BSIMM.  
  • Partner with developers, security operations, product management, and incident response teams, sharing secure-coding and vulnerability-management practices as you grow your own expertise.  

Impact Statement

For more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.: 
  • Update existing Software Security Strategy and make improvements on monitoring and reporting on KPI’s 
  • Make a significant improvement to least one automated security tool (DAST, SAST, SCA, or container scanning) in the production CI/CD pipeline, with results feeding a documented triage workflow. 
  • Driving additional Bug Bounty submissions and improve bot management turning & protections prior to end of Q3. 
  • Provide product and technology advisement and testing for new application and AI functionality 
  • Develop and plan a purposeful Application and AI development training program

Qualifications
  • 2+ years of experience in software development,  software security, or DevSecOps with security exposure — including developers looking to move into a dedicated security role — plus a Bachelor's in Information Security, Cybersecurity, Computer Science, or a related field (equivalent experience accepted in lieu of a degree).  
  • A real coding background and working knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25). 
  • Some hands-on exposure to CI/CD pipelines (GitHub, GitLab, Jenkins, or AWS DevOps) and an interest in integrating security tooling into them. 
  • Strong verbal and written communication skills, with the ability to explain security concepts to both technical and non-technical teammates. 
  • Eagerness to learn enterprise security tooling (vulnerability scanners, Bot Management, SAST/DAST/SCA) and maturity frameworks like DSOMM or BSIMM — deep prior experience with these is a plus, not a requirement. 
  • No certifications required; experience with CISSP, OSCP, GCSA, AWS Security Specialty, or CSSLP is a plus, and we'll support you in earning them. 


Compensation, Benefits, and Perks
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation. Our benefits and perks include but not limited to:
  • Restricted Stock Units (RSUs)
  • Profit Share and/or Incentive Bonus
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short-Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club