1

Bug Bounty Program Jobs (NOW HIRING)

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Senior Product Security Engineer

Austin, TX Β· On-site

$113K - $155K/yr

Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...

Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...

$84K - $115K/yr

Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...

The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...

Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions

Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...

The role partners with AI governance, development teams, and external specialists (including consultants and bug bounty programs) to ensure comprehensive adversarial coverage of the Company's AI ...

... our bug bounty program end to end: triage, response, remediation, and researcher communication β€’ Partner with Engineering to embed secure design patterns and security review into how we ship ...

Showing results 41-60

bug bounty program information

See salary details

$16

$49

$78

How much do bug bounty program jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for bug bounty program in the United States is $49.60, according to ZipRecruiter salary data. Most workers in this role earn between $31.73 and $66.83 per hour, depending on experience, location, and employer.

What is a bug bounty program?

A Bug Bounty Program is an initiative offered by organizations that invites ethical hackers and security researchers to identify and report vulnerabilities in the company’s software, websites, or systems. Participants are typically rewarded with monetary compensation, recognition, or other incentives based on the severity of the bugs they find. These programs help organizations strengthen their security by leveraging the broader cybersecurity community, thus identifying issues before malicious hackers can exploit them. Bug bounty programs are widely used by tech companies to enhance security and build trust with users.

What are some common challenges faced by professionals managing a bug bounty program?

Professionals overseeing a Bug Bounty Program often encounter challenges such as efficiently triaging a high volume of vulnerability reports, ensuring clear communication with security researchers, and balancing quick response times with thorough investigation. Additionally, maintaining strong relationships with both internal development teams and external participants is crucial for program success. Staying updated on evolving security threats and continually refining program policies are ongoing responsibilities that require adaptability and collaboration.

What are the key skills and qualifications needed to thrive as a bug bounty program participant, and why are they important?

To excel in a Bug Bounty Program, you need strong knowledge of cybersecurity fundamentals, vulnerability assessment, and web or software exploitation techniques, often backed by practical experience or certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Nmap, and Metasploit, as well as bug bounty platforms like HackerOne or Bugcrowd, is typically required. Critical thinking, persistence, and clear written communication are crucial soft skills for effectively identifying vulnerabilities and reporting them to organizations. These skills ensure you can discover security flaws efficiently, responsibly disclose them, and build a positive reputation in the cybersecurity community.

What is the difference between Bug Bounty Program vs Penetration Tester?

AspectBug Bounty ProgramPenetration Tester
CredentialsKnowledge of security vulnerabilities, bug reporting skillsCertifications like OSCP, CEH, CISSP often preferred
Work EnvironmentRemote, project-based, crowdsourcedConsulting firms, in-house teams, on-site or remote
Industry UsageTech companies, startups, open security initiativesSecurity firms, corporate security teams, government agencies
Search/Comparison IntentUnderstanding crowdsourced bug finding vs professional testingComparing freelance or company-based security assessments

The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.

More about bug bounty program jobs

What cities are hiring for Bug Bounty Program jobs?

Cities with the most Bug Bounty Program job openings:

What are the most commonly searched types of Bug Bounty Program jobs?

The most popular types of Bug Bounty Program jobs are:

What states have the most Bug Bounty Program jobs?

States with the most job openings for Bug Bounty Program jobs include:

What job categories do people searching Bug Bounty Program jobs look for?

The top searched job categories for Bug Bounty Program jobs are:

Infographic showing various Bug Bounty Program job openings in the United States as of September 2026, with employment types broken down into 25% Full Time, and 75% Contract. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $103,178 per year, or $49.6 per hour.

Cybersecurity Engineer (Remote)

Lehi, UT β€’ On-site

RainFocus
Software DevelopmentΒ β€’Β 11 - 50 employees

Full-time

Retirement, PTO

Re-posted 29 days ago


Job description

RainFocus, one of the most innovative software companies, is in search of an exceptional Cybersecurity Engineer.Β 
Β 
About RainFocus
Β 
RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market - it will be challenging, fun, and exciting.
Β 
About the Role

As a Security Engineer, you will play a critical role in safeguarding our organization's digital assets, infrastructure, and application ecosystem. This is a mid-level, autonomous role (not entry-level) where you will bridge the gap between IT operations, software development, and risk management.

You won't just be reviewing logs, settings, and configs; you will be actively replicating vulnerabilities, collaborating with developers on secure architecture, managing our bug bounty program, and keeping our security tool stack running smoothly.

Core Responsibilities
  • Vulnerability & Application Security Management: Own the vulnerability management program end-to-end: oversee continuous vulnerability scanning (Tenable) and software composition analysis/code dependencies (Sonarqube), drive remediation across teams, and replicate and validate discovered vulnerabilities using tools like Burp Suite and Kali Linux.

  • Crowdsourced Security & Threat Intel: Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight).

  • Secure Development Collaboration: Act as the security voice in developer architecture meetings. Partner with engineering teams to review code dependencies, threat-model new features, and ensure secure coding practices.

  • Risk & Change Management: Own and conduct system impact analyses for proposed changes, represent security on the Change Control Board (CCB), and lead threat modeling sessions for new systems, features, and infrastructure changes.

  • Incident Management & Operations: Triage and document security incidents within OneTrust and Jira. Collaborate with DevOps to ensure security tools are properly deployed across AWS environments and endpoint configurations.

  • Endpoint & Tool Oversight: Maintain a "read-only/audit" oversight of our endpoint detection, MDM, and email security tools (Sophos, JAMF, BetterCloud) to ensure compliance and active alerting.

  • Security Awareness & Culture: Administer the security awareness learning modules (RF Academy) and lead internal initiatives to keep security top-of-mind for all employees.

Required Skills & Qualifications
  • Citizenship: All candidates must be a US citizen.

  • Experience: 3-5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.).

  • Application Security: Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).

  • Vulnerability Assessment: Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.

  • Cloud & Infrastructure: Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications.

  • Communication: Excellent collaboration skills. You must be able to sit down with software developers, understand their sprint goals, and help them fix security bugs without breaking their workflow.

Preferred Experience & Tool Stack

Direct experience with our specific stack is a massive plus:

  • AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube

  • SecOps & Vulnerability: Tenable, Bitsight, OneTrust

  • IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud

  • Certifications: CompTIA Security+, CEH, GIAC, or progress toward a CISSP, or other relevant certifications

  • Automation: Basic scripting skills (Python, PowerShell, or Bash) to automate repetitive security tasks or log analysis.

  • Security Frameworks: Experience with maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.

  • Artificial Intelligence: Experience utilizing AI to improve productivity and efficiency, as well as experience reviewing AI tools, integrations, and features.

Success Measures
  • Proactive Remediation: Decreased time-to-remediation for vulnerabilities identified by Tenable and BugCrowd.

  • Seamless Dev Integration: Active, constructive participation in developer sprint/architecture cycles, resulting in fewer security defects reaching production.

  • Incident Readiness: Efficient tracking, documentation, and resolution of incidents within OneTrust

Success Measures
  • Reduced number of security incidents and vulnerabilities.
  • Timely and effective incident response and resolution.
  • Successful implementation and adherence to security policies and procedures.
  • Positive feedback from internal teams on security awareness and training programs.
  • Successful completion of security audits and compliance assessments.
Why work at RainFocus?
Β 
At RainFocus we delight millions of attendees at large-scale events by delivering better insights, experiences, and marketing. We were able to pivot our product and services offering in 2020 to continue growing and serving new clients and events.
Β 
As a member of the RainFocus team, you will have the opportunity to experience first-hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities.Β 
Β 
What are you waiting for? Apply today! We need more talented, hard-working, fun-loving team members just like yourself!
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job