Source Job

$121,000–$181,600/yr
United States Canada

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
  • Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.

Security Analysis Vulnerability Assessment OWASP Burp Suite Python

16 jobs similar to Security Analyst, Bug Bounty

Jobs ranked by similarity.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

$129,280–$161,600/yr
US

  • Lead, coach, and develop a team of Security Consultants while driving operational excellence and process improvements.
  • Serve as a subject matter expert in application security, incident response, and vulnerability assessment, and handle complex escalations.
  • Build strong cross-functional partnerships and stay current on security industry standards to continuously improve team capabilities.

Bugcrowd is a crowdsourced security platform that empowers organizations to stay ahead of threat actors by uniting the ingenuity of elite hackers with our patented data and AI-powered Security Knowledge Platform. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst and Rally Ventures, and we foster a diverse, inclusive culture where we value perspectives from all backgrounds.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

Brazil

  • Identify and remediate vulnerabilities across the product ecosystem using code reviews and automation.
  • Integrate security tools and practices into CI/CD pipelines to ensure secure development.
  • Collaborate with engineering teams to apply threat modeling and secure-by-design principles.

They are a partner company specializing in digital product security. The team size is not specified, but the culture emphasizes trust, collaboration, and remote work.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

Europe US Unlimited PTO

  • Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
  • Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
  • Improve secure development practices through code reviews, threat modeling, and security design reviews.

Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.

US 5w PTO

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.

NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

US Unlimited PTO 12w maternity 12w paternity

  • Monitor logs, alerts, and telemetry to detect threats across infrastructure and cloud environments.
  • Perform in-depth security analysis and investigations to assess risk and identify root causes.
  • Coordinate and execute incident response efforts including containment, mitigation, and recovery.

Binance.US is a licensed and regulated U.S. crypto platform providing secure access to over 190 cryptocurrencies. As a remote-first team, we innovate to bridge traditional finance and Web3, helping bring financial freedom within reach for all.

Global

  • Serve as Incident Commander for SIRN security cases, owning coordination from detection to resolution.
  • Lead incident triage, rapidly assessing scope, severity, and impact to drive prioritization.
  • Develop, tune, and triage telemetry signals for on-chain and infrastructure detection.

Asymmetric Research is a boutique security venture specializing in deep partnerships with L1/L2 blockchains and DeFi protocols. Their fully remote team brings decades of security-first experience from top tech companies, valuing autonomy and professionalism.

Global Unlimited PTO

  • Conduct application security reviews including threat modeling, code review, and risk assessment for new features.
  • Perform and improve SAST/DAST operations, triage, validation, and remediation tracking in CI/CD pipelines.
  • Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces.

Monarch is a powerful, all-in-one personal finance platform designed to simplify money management. They are a fully remote team of do-ers led by experienced entrepreneurs, passionate about building a product people love.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.