Cybersecurity Engineer (Remote)
Lehi, UT Β· On-site
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Lehi, UT Β· On-site
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Lehi, UT Β· On-site
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Austin, TX Β· On-site
$113K - $155K/yr
Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
Austin, TX Β· On-site
$113K - $155K/yr
Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
Lehi, UT Β· Remote
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Quick apply
Lehi, UT Β· Remote
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
San Francisco, CA Β· On-site +1
Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...
San Francisco, CA Β· On-site +1
Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage ...
Austin, TX Β· On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Austin, TX Β· On-site
$212K - $319K/yr
You will combine hands-on technical leadership with people management, overseeing programs that include subcomponents of Apple's bug bounty program, proactive vulnerability discovery, WAF rule ...
Lehi, UT Β· On-site +1
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Lehi, UT Β· On-site +1
Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight). * Secure Development Collaboration: Act as the security voice in ...
Partner cross-functionally with Product Engineering, Legal, Security Engineering Platform, Data teams and XFN partners to execute rigorous, agent enabled cross-brand Bug Bounty Program, Penetration ...
Partner cross-functionally with Product Engineering, Legal, Security Engineering Platform, Data teams and XFN partners to execute rigorous, agent enabled cross-brand Bug Bounty Program, Penetration ...
$84K - $115K/yr
Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...
$84K - $115K/yr
Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing * Drive implementation and usage of engineering security tools - static, dynamic ...
San Francisco, CA Β· On-site
$150K - $220K/yr
Shape Persona's presence in the security research community - running the bug bounty program that powers it Must-haves * 4+ years of software engineering experience * 2+ years in product security
San Francisco, CA Β· On-site
$150K - $220K/yr
Shape Persona's presence in the security research community - running the bug bounty program that powers it Must-haves * 4+ years of software engineering experience * 2+ years in product security
Atlanta, GA Β· On-site
The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...
Atlanta, GA Β· On-site
The role supports the company's Vulnerability Disclosure Program (VDP, Bug Bounty Program (BBP) and Attack Surface Management (ASM) operations - assessing incoming reports, confirming they are valid ...
San Francisco, CA Β· On-site
Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions
Quick apply
San Francisco, CA Β· On-site
Experience in Red Teaming and bug bounty programs preferred Ideal Candidate: * 5-8 years of security testing experience * Proven ability to mentor teams and implement enterprise security solutions
San Francisco, CA Β· On-site +1
Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...
San Francisco, CA Β· On-site +1
Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program * Security ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
The role partners with AI governance, development teams, and external specialists (including consultants and bug bounty programs) to ensure comprehensive adversarial coverage of the Company's AI ...
The role partners with AI governance, development teams, and external specialists (including consultants and bug bounty programs) to ensure comprehensive adversarial coverage of the Company's AI ...
... of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business lines and vendors Policy and Procedures - Assist in ...
... of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business lines and vendors Policy and Procedures - Assist in ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manage Bug Bounty - Ability to manage various aspects of a bug bounty program, including but not limited to engaging with submissions and responses, testing/retesting and partnering with business ...
Manhattan, NY Β· On-site
$405K - $485K/yr
Oversee Anthropic's bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with ...
Manhattan, NY Β· On-site
$405K - $485K/yr
Oversee Anthropic's bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with ...
Manhattan, NY Β· On-site
... our bug bounty program end to end: triage, response, remediation, and researcher communication β’ Partner with Engineering to embed secure design patterns and security review into how we ship ...
Manhattan, NY Β· On-site
... our bug bounty program end to end: triage, response, remediation, and researcher communication β’ Partner with Engineering to embed secure design patterns and security review into how we ship ...
$16.35 - $22.01
6% of jobs
$22.01 - $27.67
14% of jobs
$31.30 is the 25th percentile. Wages below this are outliers.
$27.67 - $33.33
7% of jobs
$33.33 - $38.99
1% of jobs
$38.99 - $44.65
13% of jobs
The median wage is $47.88 / hr.
$44.65 - $50.31
15% of jobs
$50.31 - $55.97
3% of jobs
$55.97 - $61.63
9% of jobs
$65.30 is the 75th percentile. Wages above this are outliers.
$61.63 - $67.29
11% of jobs
$67.29 - $72.95
15% of jobs
$72.95 - $78.61
6% of jobs
$16
$49
$78
| Aspect | Bug Bounty Program | Penetration Tester |
|---|---|---|
| Credentials | Knowledge of security vulnerabilities, bug reporting skills | Certifications like OSCP, CEH, CISSP often preferred |
| Work Environment | Remote, project-based, crowdsourced | Consulting firms, in-house teams, on-site or remote |
| Industry Usage | Tech companies, startups, open security initiatives | Security firms, corporate security teams, government agencies |
| Search/Comparison Intent | Understanding crowdsourced bug finding vs professional testing | Comparing freelance or company-based security assessments |
The main difference is that Bug Bounty Programs are crowdsourced initiatives where individuals report vulnerabilities remotely, often without formal certifications. Penetration Testers are professionals with certifications who perform targeted security assessments, usually in a consulting or in-house setting. Both roles focus on identifying security flaws but differ in structure, credentials, and work environment.
Cities with the most Bug Bounty Program job openings:
The most popular types of Bug Bounty Program jobs are:
States with the most job openings for Bug Bounty Program jobs include:
The top searched job categories for Bug Bounty Program jobs are:

Lehi, UT β’ On-site
Full-time
Retirement, PTO
Re-posted 29 days ago
As a Security Engineer, you will play a critical role in safeguarding our organization's digital assets, infrastructure, and application ecosystem. This is a mid-level, autonomous role (not entry-level) where you will bridge the gap between IT operations, software development, and risk management.
You won't just be reviewing logs, settings, and configs; you will be actively replicating vulnerabilities, collaborating with developers on secure architecture, managing our bug bounty program, and keeping our security tool stack running smoothly.
Vulnerability & Application Security Management: Own the vulnerability management program end-to-end: oversee continuous vulnerability scanning (Tenable) and software composition analysis/code dependencies (Sonarqube), drive remediation across teams, and replicate and validate discovered vulnerabilities using tools like Burp Suite and Kali Linux.
Crowdsourced Security & Threat Intel: Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight).
Secure Development Collaboration: Act as the security voice in developer architecture meetings. Partner with engineering teams to review code dependencies, threat-model new features, and ensure secure coding practices.
Risk & Change Management: Own and conduct system impact analyses for proposed changes, represent security on the Change Control Board (CCB), and lead threat modeling sessions for new systems, features, and infrastructure changes.
Incident Management & Operations: Triage and document security incidents within OneTrust and Jira. Collaborate with DevOps to ensure security tools are properly deployed across AWS environments and endpoint configurations.
Endpoint & Tool Oversight: Maintain a "read-only/audit" oversight of our endpoint detection, MDM, and email security tools (Sophos, JAMF, BetterCloud) to ensure compliance and active alerting.
Security Awareness & Culture: Administer the security awareness learning modules (RF Academy) and lead internal initiatives to keep security top-of-mind for all employees.
Citizenship: All candidates must be a US citizen.
Experience: 3-5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.).
Application Security: Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
Vulnerability Assessment: Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.
Cloud & Infrastructure: Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications.
Communication: Excellent collaboration skills. You must be able to sit down with software developers, understand their sprint goals, and help them fix security bugs without breaking their workflow.
Direct experience with our specific stack is a massive plus:
AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube
SecOps & Vulnerability: Tenable, Bitsight, OneTrust
IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud
Certifications: CompTIA Security+, CEH, GIAC, or progress toward a CISSP, or other relevant certifications
Automation: Basic scripting skills (Python, PowerShell, or Bash) to automate repetitive security tasks or log analysis.
Security Frameworks: Experience with maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.
Artificial Intelligence: Experience utilizing AI to improve productivity and efficiency, as well as experience reviewing AI tools, integrations, and features.
Proactive Remediation: Decreased time-to-remediation for vulnerabilities identified by Tenable and BugCrowd.
Seamless Dev Integration: Active, constructive participation in developer sprint/architecture cycles, resulting in fewer security defects reaching production.
Incident Readiness: Efficient tracking, documentation, and resolution of incidents within OneTrust
Sourced by ZipRecruiter
Software development
11 - 50 Employees
Lehi, UT, US
2013