1

Top Bug Bounty Jobs (NOW HIRING)

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security ... Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure ...

... AI RMF, MITRE ATLAS, OWASP Top 10 for LLMs, and emerging industry standards. * Build ... Coordinate with external consultants, specialized AI security firms, and bug bounty programs for AI ...

... top security firm, or equivalent. * Hands-on adversarial experience: jailbreaking or stress-testing frontier models, prompt injection research, offensive security, penetration testing, bug bounty ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security ... Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security ... Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure ...

Product Security Engineer II

$60.25 - $80.25/hr

Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling ... OWASP Top 10 issues, authentication and authorization flaws, injection, insecure design, secrets ...

The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and ... Working knowledge of common web/application vulnerability classes (e.g., OWASP Top 10) and the ...

Best in Business, and LinkedIn Top Startups. Your Role The Security team at Zip is responsible for ... Validate, triage, and coordinate security findings from bug bounty, third-party pentests, and cloud ...

Showing results 41-60

Top Bug Bounty information

What cities are hiring for Top Bug Bounty jobs?

Cities with the most Top Bug Bounty job openings:

What states have the most Top Bug Bounty jobs?

States with the most job openings for Top Bug Bounty jobs include:

What job categories do people searching Top Bug Bounty jobs look for?

The top searched job categories for Top Bug Bounty jobs are:

Infographic showing various Top Bug Bounty job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 19% Part Time, and 8% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Security Penetration Tester, Frontier AI Evaluation (Contract)

Cobalt

Sunnyvale, CA • On-site

Other

Posted 6 days ago


Job description

About the role:

Cobalt is seeking experienced penetration testers to contribute expert reasoning, technical problems, and evaluation data used to train and assess frontier AI models on security tasks.

This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal security teams, or independent practice.

You do not need prior experience in data annotation or AI research. What matters is that you can find and reason about real weaknesses in software and infrastructure unaided, and that you can document how you got there clearly enough for another practitioner to follow.

All work is performed against sandboxed environments, purpose-built targets, and model endpoints supplied by us or by the lab. We do not accept work performed against systems you are not authorized to test, and we do not accept material covered by a client agreement or obtained without authorization.


What you'll do:

Depending on the project, you may:

  • Produce written testing traces, capturing how you form and test hypotheses, what you rule out and why, and how you arrive at a working approach, rather than only the end result
  • Author novel security problems, capture-the-flag style challenges, and lab environments with verifiable success criteria
  • Evaluate model-generated security content and code, ranking responses, explaining what makes the stronger one stronger, and identifying the specific step at which the technical reasoning breaks down
  • Assess whether stated findings are supported by the underlying evidence, and identify inconsistencies between reported results and what the target actually does
  • Design rubrics and partial-credit criteria for scoring multistep testing and remediation tasks

Projects follow their own guidelines, scope rules, and quality standards, and you will work with feedback from reviewers and lab research teams.


Required qualifications:

  • Demonstrable penetration testing experience, evidenced by professional engagements, published vulnerability research or CVEs, a substantive bug bounty record, competitive CTF results, or comparable work
  • Strong hands-on coding ability in at least one of Python, C, C++, Go, Rust, or JavaScript, sufficient to read unfamiliar codebases and write your own tooling rather than only running existing tools
  • Depth in at least one area, for example web and API security, cloud and container security, network and infrastructure testing, mobile security, or binary exploitation
  • Ability to explain each step of your reasoning clearly in writing, and to produce documentation another practitioner could reproduce
  • Willingness to work strictly within defined scope and authorization, and to sign a confidentiality agreement covering project materials

Certifications such as OSCP, OSWE, OSEP, GPEN, or GXPN are useful but not required.


Why join Cobalt AI:

  • Advance frontier AI where it counts. Apply your security expertise to data that frontier labs cannot obtain any other way, where your judgment directly shapes how the next generation of models reasons about security.
  • Grow professionally. Expand your influence through evaluation projects, advisory roles, and research collaborations, while developing a working understanding of how frontier models are trained and assessed.
  • Work with a top-tier network. Collaborate with security engineers and researchers from leading organizations on high-impact, flexible work.
  • Set your own schedule. Flexible 10 to 40 hour weeks that fit around your existing engagements and your life.
  • Competitive pay. Rates vary by project and are determined by a number of factors, including scope, skillset, and experience.