1

Bug Bounty Program Jobs (NOW HIRING)

Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of ...

NY · On-site

$120 - $150/hr

Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. * Collaborate with Dev/QA teams throughout the ...

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Shape Persona's presence in the security research community -- running the bug bounty program that powers it. Must-haves * 4+ years of software engineering experience. * 2+ years in product security.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Red Team Engineer/ Offensive Security Lead

$104K - $138K/yr

You will also assume ownership of security stage-gates within our CI/CD pipeline and support the operation of our internal Bug Bounty Program. If you've spent years thinking like an adversary and you ...

Showing results 41-60

bug bounty program information

See salary details

$16

$49

$78

How much do bug bounty program jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

More about bug bounty program jobs

What cities are hiring for Bug Bounty Program jobs?

Cities with the most Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Bug Bounty Program jobs?

States with the most job openings for Bug Bounty Program jobs include:

Infographic showing various Bug Bounty Program job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Security Engineer, Application Security at Mercor Alabaster New York, NY

Fairweather, LLC

Manhattan, NY • On-site

$140 - $200/hr

Other

Medical, Dental, Vision

Posted 4 days ago


Job description

Mercor Alabaster. New York, NY.

Security Engineer, Application Security job at Mercor. Mercor's mission is to organize human intelligence to power the AI economy. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $3 million a day. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You'll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build:
  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
  • Vulnerability management processes that prioritize by real exploitability, not CVSS score
  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
What We're Looking For
  • You've found and fixed real vulnerabilities in production applications - not just run scanners
  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Bonus Points
  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills - you've done penetration testing and can think like an attacker
  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
  • You've built custom security tooling that a team still uses
  • Contributions to open source security projects or published vulnerability research
Why Mercor
  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
  • Benefits
    • Bi-annual performance bonus structure
    • Generous equity grant vested over 4 years
    • Up to $15k Relocation bonus
    • $10K housing bonus (if you live within 0.5 miles of our office)
    • $1.5K monthly stipend for meals
    • Free Equinox membership
    • $200 monthly laundry reimbursement
    • $200 monthly personal wellness reimbursement
    • Health, Dental, Vision insurance
#J-18808-Ljbffr