Security Program Manager (Part Time)
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
Bugcrowd is seeking a versatile security technical program manager to drive multiple keystone programs and ensure the engineering team continues down a path of success. You will drive multiple programs, drive a culture of accountability, and enable engineering to own security. The role requires excellent communication skills as the cybersecurity department liaises with all other departments within the company.
Essential Duties and Responsibilities
- Own the Vulnerability Management Program: With the support of the security engineering team, prioritize, communicate, and drive a culture of ownership across business units for security issues
- Drive Metrics and Program Review: Leverage metrics and regular program review to transparency communicate performance and drive accountability with both peer teams and upper management
- Project Leadership: Provides expert leadership to highly visible and multi-faceted projects while motivating and fostering coordination across teams. Work closely with Software Engineers, Engineering leaders, Product Managers and other teams across geographies (US, IN, AUS)
- Continuous Improvement: Build and improve project management tools, ongoing practices and mentor the team around best practices
- Business Management: Help with organizational functions such as calendar management and vendor coordination for TISO and CI&SO.
Education, Experience, Knowledge, Skills, and Abilities
- Bachelor's degree in engineering, computer science or relevant field, or equivalent practical experience.
- 5+ years of experience in technical program management.
- 2+ years exposure to security (preferred), site reliability engineering, or software engineering
- Ability to understand IT concepts such as web applications and servers, and be relatively tech savvy
Working Conditions and Physical Requirement
- The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
- Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
- Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
- Environment - remote, work-from-home 100% of the time
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent.
The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business. The national estimate for the current hourly range for this position is $40.92 - $51.15 per hour.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Manager, Engineering - AI and Data Team Manager
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
We’re seeking a hands-on Manager for the AI and Data Science team. This role will manage a high-performing team dedicated to developing data-driven and AI-powered systems that significantly enhance our offensive security capabilities. Your primary focus (70%) will be on setting the technical direction, working with the team in building scalable data pipelines, and training and deploying predictive models to solve complex cybersecurity challenges. This leadership role also includes mentoring and managing the team. This position is ideal for someone who excels in the technical execution of AI and Data engineering and is ready to lead the development of our next-generation, AI-driven preemptive cybersecurity product alongside a group of exceptional engineers.
Essential Duties and Responsibilities
- Lead Technical Strategy & Execution: Define and drive the technical roadmap for AI, ML, and data systems, overseeing development, deployment, and operationalization to ensure robust performance, scalability, and direct alignment with key business strategy and requirements.
- Team Leadership & Mentorship: Lead, mentor, and grow a small high-performing team of data scientists and ML engineers, cultivating a culture of technical excellence, accountability, and continuous learning.
- AI/ML/Generative Systems Development: Direct the entire lifecycle—from design to deployment—of robust data pipelines, scalable model training, and innovative AI/ML applications. Focus on leveraging these systems to significantly boost analyst and hacker productivity across critical offensive security use cases.
- Model Development and Platform Integration: Guide the development, tuning, deployment, and MLOps of Machine Learning models for cybersecurity. Ensure secure and compliant integration of cutting-edge generative AI models (via platforms like AWS Bedrock, OpenAI, Anthropic) with internal APIs and sensitive security datasets.
- Data and Software Architecture: Architect, govern, and optimize large-scale, high-performance data pipelines and overall software architecture essential for securely and efficiently processing massive vulnerability, asset, and activity datasets sourced from various environments.
- Security & Scalability Partnership: Collaborate closely with infrastructure teams to architect AI workloads and data pipelines that meet stringent requirements for security, efficiency, and scalability, particularly within multi-tenant and regulated environments (e.g., FedRAMP, SOC2).
- Cross-Functional Collaboration: Serve as the primary technical subject matter expert and liaison, partnering with security research, product, and platform teams to translate complex offensive security challenges into robust, data-driven automation and intelligence solutions.
- Continuous MLOps Improvement: Establish and manage best-in-class MLOps practices, including CI/CD pipelines, comprehensive evaluation frameworks, and robust monitoring/observability tools to ensure the continuous improvement and reliability of all data and AI systems.
- API Design & Integration: Oversee the design of robust, high-availability APIs and interfaces that facilitate seamless, scalable interaction between LLM agents and internal systems (such as the MCP server) for crucial tasks like search, data enrichment, and automated decision support.
Education, Experience, Knowledge, Skills, and Abilities
- 5+ years of experience in Data Science, ML Engineering, or Data Engineering, with 2+ years in a technical leadership or team lead role.
- Strong architectural understanding of LLM technologies, RAG architectures, prompt engineering, ML Ops, and secure API integration with AI systems.
- Deep expertise with Python, AWS services (S3, Lambda, Batch, Glue, Bedrock, Step Functions, Redshift), and ML frameworks.
- Proven experience successfully leading a team to build and deploy end-to-end ML pipelines—from data ingestion to model deployment, monitoring, and MLOps.
- Ability to design, manage, and govern secure data-driven software architectures for large-scale, multi-tenant, and high-security environments.
- Excellent communication skills with a demonstrated ability to mentor engineers, influence technical direction, and present complex concepts to both technical and non-technical audiences.
Preferred Experience
- Deep knowledge of offensive security workflows (bug bounty, vulnerability research, red teaming) and the associated datasets.
- Experience successfully deploying and operating AI solutions within regulated environments (FedRAMP, SOC2).
- Experience and knowledge of software security
- Master’s degree or higher in Computer Science, Information Systems, or a related quantitative field.
Working Conditions and Physical Requirements
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is: $172,000 - $236,500.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Staff Product Manager (AI & Data)
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
We are looking for an innovative Staff Product Manager, AI & Data to define the vision, strategy, and roadmap for Bugcrowd’s data and intelligence backbone. In this role, you will be the "Architect of the Signal," building the platform that turns a flood of raw test results, including vulnerability scans, penetration tests (J5), and bug bounty/VDP submissions, into validated, correlated, and prioritized intelligence customers can trust and act on. Your mission is to eliminate noise before it ever reaches a customer, connect the dots across every test type and source, and make sure the highest-risk issues, and the clearest path to fixing them, always rise to the top. You will sit at the intersection of data engineering, security operations, and applied AI/ML, owning the full lifecycle from raw test result to remediation guidance.
Essential Duties and Responsibilities
- AI & Data Strategy & Vision: Own the vision, strategy, and roadmap for Bugcrowd’s AI & Data pillar. Define how validation, aggregation, prioritization, and recommendations fit together into one trusted data platform.
- Validation as a Service: Design and scale an automated triage and deduplication capability. It validates test results across all test types (vulnerability scanning, penetration testing, MBB/VDP) before they enter the data platform. Only clean, trustworthy signal reaches downstream products.
- Aggregation & Correlation: Build the data models and pipelines that aggregate and correlate validated findings across test types and sources. The result is a single, unified view of a customer’s risk posture.
- Prioritization & Diagnosis: Develop the logic that diagnoses what matters most. Look within a customer across test results, across customers, and against third-party and internal threat feeds. The highest-impact issues should always surface first.
- Recommendation Engine: Partner with engineering to turn a diagnosis into action. Surface a suggested code fix. Confirm whether the customer’s logging can even detect the issue. Deliver a ready-to-use detection rule (e.g., Splunk) and a threat hunting query to check for past abuse.
- Cross-Functional Intelligence: Work closely with our Agentic Products PM team. Feed new attack vectors and data sources back into agent training. Help our agents learn to “look for the new thing.”
- Platform Trust & Scalability: Define and own the metrics that prove the platform works: validation accuracy, deduplication rate, time-to-diagnosis. These metrics make the AI & Data pillar the trusted foundation every other product is built on.
Education, Experience, Knowledge, Skills, and Abilities
- 7+ years of Product Management experience. Ideally this spans both security/vulnerability and threat data domains and ML/data platform and pipeline domains. That’s a rare blend, but it’s the ideal for this role.
- Data-Minded Systems Thinker: You’re comfortable with data models, pipelines, and deduplication/correlation logic. You can translate messy, multi-source data into a structured, trustworthy output.
- Security Domain Fluency: You understand how different test types (vulnerability scanning, penetration testing, bug bounty/VDP) generate findings. You know what it takes to triage, validate, and prioritize them correctly.
- Strategic Leader: You’ve been a contributor at the executive team level with the ability to build trust at every level and rally teams toward a long-term data strategy.
- Tactical Execution: You balance the ambition of “one platform, one source of truth” with the pragmatic need to ship trustworthy improvements today.
Preferred Experience
- Detection Engineering Familiarity: Exposure to writing or reviewing SIEM/Splunk-style detection rules and threat hunting queries.
- ML/AI for Data Correlation: Experience building or product-managing systems that use ML for entity resolution, deduplication, anomaly detection, or risk scoring.
- Security Testing Landscape: Familiarity with vulnerability scanning, penetration testing, and bug bounty/VDP program mechanics.
- The “Builder” Edge: You are an active user of AI-native tools (Claude Code, Cursor, etc.) and likely have “robots” of your own running in your personal workflows.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is: $145,440 - $181,800.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Director, Technical Solutions
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
The Director, Technical Solutions is a senior leadership role at Bugcrowd, responsible for setting the strategic direction and priorities for the global technical sales and solution architecture function.
The Director will define the vision for pre-sales technical engagements, ensuring that solution recommendations and demonstrations for Commercial and Field Accounts align with overarching business goals. Beyond technical execution, the Director is responsible for organizational effectiveness, managing departmental budgets, and driving cross-functional collaboration with Sales, Product, Engineering, and Marketing to ensure a seamless, expert "front door" for all customer engagements.
Essential Duties and Responsibilities
- Set strategic direction and annual priorities for the global Technical Solutions department.
- Manage and mentor a global team of managers and senior contributors, fostering high performance and excellence.
- Establish and track departmental KPIs, success metrics, and operational budgets aligned with company growth targets.
- Oversee global methodology for pre-sales technical engagements, scoping, and solution architecture design.
- Develop and standardize global product demonstration and technical presentation assets to ensure consistent value delivery.
- Act as executive technical sponsor for key accounts to resolve high-level strategic roadblocks.
- Partner with Product and Engineering leadership to translate customer trends and technical gaps into long-term product roadmaps.
- Coordinate with Sales and Marketing to develop enterprise-level collateral, best practices, and enablement training.
- Drive operational excellence and post-sale handover, utilizing automation to resolve technical escalations and improve systemic performance.
Education, Experience, Skills, & Abilities
- 6+ years of experience in a customer-facing technical leadership role (e.g., Solutions Architecture, Sales Engineering, or Technical Program Management), with at least 3+ years in a manager-of-managers capacity.
- Demonstrated success in setting departmental vision, managing global remote teams, and architecting solutions for enterprise-level, multi-national customers.
- Subject matter expertise in Offensive Security, including Penetration Testing, Bug Bounty, and Red Teaming methodologies.
- Exceptional ability to translate complex technical concepts into clear business-value propositions for executive-level audiences.
- Advanced experience with CRM platforms, project management frameworks, and the development of technical governance documentation.
Preferred Experience
- Prior experience working within the technology and cybersecurity vendor space, particularly in offensive security services.
- Proven track record of driving operational efficiency through automation and process optimization.
- Bachelor’s or Master’s degree in Computer Science, Engineering, or a related technical field, or equivalent practical leadership experience.
Working Conditions and Physical Requirements
- The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
- Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
- Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
- Environment - remote, work-from-home 100% of the time.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is: $147,200 - $184,000.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Reinforcement Learning Engineer (Cybersecurity)
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
The Bugcrowd RL and Reasoning Team focuses on pushing the boundaries of autonomous cybersecurity by building authentic reinforcement learning environments for foundational model companies. As a Reinforcement Learning Engineer you will advance the frontier of AI Reinforcement Learning development and delivery. You will build the infrastructure and tooling that transforms real-world vulnerability research into large-scale reinforcement learning environments used to train next-generation AI systems.
This role is unique. You will help create the training environments that teach AI systems how to hack and defend software. Your work will directly influence the capabilities of the next generation of AI models. Instead of building a single application, you will build the infrastructure that generates thousands of environments used to train frontier AI systems.
Our team works at the intersection of AI, security research, and systems engineering, building environments that allow models to learn skills such as vulnerability discovery, exploitation, and remediation.
Essential Duties and Responsibilities
If you enjoy building high-performance systems that power cutting-edge AI research, this role is for you.
This role focuses on building the systems that generate RL environments, not just the environments themselves. You will design pipelines that ingest software projects, analyze them with Bugcrowd’s Mayhem platform, and automatically construct training environments used by frontier AI labs including Anthropic, OpenAI, and Cohere.
The ideal candidate is a strong systems engineer who understands:
- Reinforcement learning workflows
- Building clean, reproducible Linux ML environments (containers, MCP, etc)
- System security background in binary exploitation, such as buffer overflows, fuzzing, exploitation, and x86/64.
- Experience developing applications in Python and C, with Rust a plus.
Education, Experience, Knowledge, Skills, and Abilities
Understanding of RL training workflows used by modern LLM systems
- Experience with DevOps pipelines (e.g., github actions), reproducible builds (docker, buildkit, nix).
- Proficiency in Python and C. Other languages (especially Rust) are a plus.
- Understanding of software vulnerabilities, fuzzing, or program analysis
- Experience with build systems and large open-source codebases
- Comfort working with Linux systems and low-level debugging
- Experience working with benchmark environments (CTFs, SWE-bench, security challenges, etc.) is a plus
Working Conditions and Physical Requirements
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position of $176,400 - $242,550.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Technical Delivery Manager 2 (Technical Engagement Manager 2)
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
Bugcrowd is seeking a highly skilled Technical Engagement Manager 2 (TEM2) to join our team and own the technical onboarding, implementation and rollout of our Bug Bounty, Vulnerability Disclosure and Pentest programs for our customers.
As a key technical resource, you will work closely with customers and internal teams to ensure successful program launches and ongoing adoption. You’ll serve as a trusted advisor on technical aspects of Bugcrowd’s platform and security delivery models, helping customers configure and operationalize their security programs.
Essential Duties and Responsibilities
Technical Implementation and Onboarding
- Lead the end to end technical onboarding and configuration of Bug Bounty, Vulnerability Disclosure, Red team and pentest programs for new and existing customers.
- Translate customer security requirements into tailored program designs and platform configurations.
- Conduct technical program reviews, kickoff meetings, and walkthroughs with customers and internal stakeholders
- Troubleshoot technical issues related to platform integrations, vulnerability workflows and reporting.
Customer Engagement and Support
- Act as a technical point of contact during program launches, ensuring smooth transitions and early success
- Provide expert guidance on offensive security engagements, vulnerability triage, communication workflows, and integration best practices
- Collaborate closely with the Customer Relationship Managers and sales teams to align technical delivery with customer expectations.
Cross Functional Collaboration
- Partner with Line of Business Owners, Product, Engineering and Operations team to relay customer feedback and advocate for feature enhancements
- Assist in developing and improving internal onboarding playbooks, technical documentation, and enablement materials.
- Support continuous improvement of delivery processes to drive consistency, quality and scalability.
Subject Matter Expertise
- Maintain deep expertise in Bugcrowd’s platform capabilities, bug bounty program models, and pentesting methodologies.
- Stay informed on industry trends and evolving security practices to provide innovative customer solutions.
Education, Experience, Knowledge, Skills, and Abilities
- 4+ years of experience in a customer-facing technical role such as implementation, solutions architecture, technical program management, or professional services.
- Deep knowledge of pentest, bug-bounty and red-team methodologies.
- Strong problem solving skills and ability to manage multiple projects simultaneously
- Excellent written & verbal communication with customer facing mindset
- Ability to work collaboratively in a cross functional environment.
Working Conditions and Physical Requirements
- The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
- Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
- Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
- Environment - remote, work-from-home 100% of the time.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is: $85,120 - $106,400.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Enterprise Account Executive
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
The Enterprise Account Executive (AE) at Bugcrowd is responsible for developing and executing a strategic sales plan to acquire new enterprise customers and expand existing relationships within a defined territory. You will be instrumental in positioning Bugcrowd's platform and services as essential components of a modern, proactive security strategy.
Essential Duties and Responsibilities
- Drive the full sales cycle from prospecting and lead qualification to negotiation and closing multi-million dollar deals within the enterprise segment.
- Develop and maintain a strong understanding of the cybersecurity landscape, competitive offerings, and Bugcrowd's unique value proposition.
- Establish strong relationships with key stakeholders, including CISO/VP-level security executives, procurement, and technical teams.
- Accurately forecast sales opportunities and maintain a robust pipeline using CRM tools (e.g., Salesforce).
- Collaborate cross-functionally with Sales Engineering, Customer Success, and Product teams to ensure a seamless customer experience.
- Create and deliver compelling, customized sales presentations and proposals that clearly articulate the ROI of Bugcrowd's solutions.
- Represent Bugcrowd at industry conferences, trade shows, and customer events to build brand awareness and generate new leads.
- Negotiate contracts and commercial terms effectively, ensuring favorable outcomes for both the customer and Bugcrowd.
Education, Experience, Knowledge, Skills, and Abilities
- 5+ years of successful quota-carrying sales experience selling complex B2B SaaS solutions, preferably in the cybersecurity or risk management space.
- Demonstrated history of consistently achieving or exceeding annual sales targets ($1M+ quota) in an Enterprise or Strategic Account role.
- Expertise in managing large, complex sales cycles (6-12 months) and navigating multi-threaded organizational structures.
- Proven ability to prospect, build pipeline, and close deals with Fortune 500/Global 2000 organizations.
- Strong understanding of modern security testing methodologies (e.g., pen testing, bug bounty, vulnerability disclosure).
Preferred Experience
- Prior experience selling crowdsourced security, Bug Bounty, or Attack Surface Management solutions.
- Familiarity with Salesforce and sales engagement tools.
- A four-year degree from an accredited university.
Working Conditions and Physical Requirements
- The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
- Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
- Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
- Environment - remote, work-from-home 100% of the time.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is: $116,800. - $160,600.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Product Security Engineering Manager
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
As a Product Security Engineering Manager, you will set strategy and lead execution of our application security, platform security, and federal (FedRAMP) programs. You will grow and mentor a geographically distributed team of security engineers. If you are passionate about building secure-by-default systems, embedding security throughout engineering, and love getting your hands dirty in the technical details while empowering a team, we want to meet you.
Essential Duties and Responsibilities
- Drive Team Excellence: Lead, grow, and empower a high-performing team of product security engineers, fostering a culture of engineering excellence, psychological safety, and continuous learning
- Drive the Secure SDLC: Own and evolve our secure development lifecycle. You will drive "shift-left" initiatives across architecture reviews, threat modeling, SAST/DAST, continuous end-to-end testing, and advanced fuzzing
- Architect Secure Foundations: Design and launch a Security Foundations program focused on secure-by-default engineering. Your goal isn't just to find bugs, but to systematically eradicate entire classes of vulnerabilities through paved roads and developer guardrails
- Spearhead FedRAMP Initiatives: Own the security roadmap and day-to-day operations of our FedRAMP program
Education, Experience, Knowledge, Skills, and Abilities
Experience & Leadership
- Deep Technical Background: 7+ years of experience in cybersecurity, with a focus on Product Security, Application Security, or Platform Security
- Leadership Experience: 2+ years of experience directly managing and mentoring a team of security engineers
- Program and Project Management: Demonstrable experience driving sustained improvement and managing complex projects that span multiple teams and business units
- Clear Communication: Excellent communication skills with a proven ability to build strong partnerships with software engineering, DevOps, and product management teams, and operations teams
Technical Skills
- Secure SDLC Mastery: Deep, hands-on experience integrating security into modern CI/CD pipelines. You are highly proficient in threat modeling, architecture reviews, implementing automated testing (SAST, DAST, SCA, Fuzzing), and SDLC program management
- Software Engineering: Fluency in at least one or more modern programming languages (e.g., Python, Go, Ruby, Java) to facilitate code reviews, script automation, and build out security tooling
- Cloud & Platform Security: Strong understanding of cloud-native architectures (AWS, GCP, or Azure), containerization (Kubernetes, Docker), Linux, and Infrastructure as Code (Terraform)
- Compliance as Engineering: Practical experience supporting compliance requirements such as Fedramp (preferred), PCI, SOC2, ISO27001, NIST 800-53
Bonus Points (Preferred but not required)
- Previous experience managing, triaging, or actively participating in Bug Bounty programs
- A background in building "paved roads" or secure-by-default internal libraries to eliminate entire classes of vulnerabilities
- Experience working within a fast-paced, high-growth security or SaaS company
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent.
The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business. The national estimate for the current base range for this position is $176,000 - $242,000.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
Cleared Vulnerability Research Engineer
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
This role is focused on end-to-end exploit development for real-world targets. The specialist will design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems. Work is conducted at the operating system, binary, and micro-architectural levels, with a strong emphasis on creating new technical capabilities. Success in this position requires the ability to independently translate an under-defined mission objective into a concrete, technically novel capability and the comfort of operating with minimal supervision, incomplete problem definitions, and delayed feedback.
Education, Experience, Knowledge, Skills, and Abilities
- Design, develop, and validate novel vulnerability discovery and exploitation capabilities.
- Conduct expert reverse engineering of binaries (x86-64, ARM64, etc.) using industry-standard tools.
- Identify and exploit real-world vulnerabilities such as Use-after-free, Type confusion, Integer truncation, and Buffer overflow.
- Demonstrate ability to discover new, novel vulnerabilities in complex systems.
- Rapidly understand current vulnerability research and apply findings to identify new instances of vulnerability classes.
- Employ both manual analysis and automated techniques (e.g., fuzzing) for vulnerability discovery.
- Code and debug complex functions in C, Python, and Assembly (x86-64, ARM, etc.).
- Independently manage and execute research objectives, including scoping, research, experimentation, validation, and iteration.
- Travel to customer sites as required.
- Perform on-site for extended periods of time.
Education, Experience, Knowledge, Skills, and Abilities
- Exploit Development:
- Expertise in reverse engineering of binaries (x86-64, ARM64, etc) using tools such as Binary Ninja, Ghidra, or IDA Pro.
- Precise understanding of stack and heap objects and exploit-relevant vulnerabilities (e.g., Use-after-free, Type confusion, Integer truncation, Buffer overflow).
- Vulnerability Discovery:
- Demonstrated ability to discover new vulnerabilities, not just exploit known ones.
- Experience with both manual analysis and automated techniques (e.g., fuzzing).
- Languages:
- Ability to code and debug C, Python, and Assembly (x86-64, ARM, etc).
- Research Ownership & Autonomy:
- Ability to independently translate an under defined mission objective into a concrete, technically novel capability.
- Comfort operating with minimal supervision.
- Clearance & Logistics:
- TS/SCI clearance required (inactive SCI acceptable if SCI-clearable).
- Ability to travel to customer sites as required.
Working Conditions and Physical Requirements
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home with travel to customer location in Alabama to perform work in cleared spaces.
Pay Range Disclosure
At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.
The national estimate for the current base range for the position is $154,800 - $193,500.
This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at: https://www.bugcrowd.com/about/careers/
The full posting opens here — pay, setting and the full description, without leaving the list.