1,051,596open jobs
61,700companies
177,096added this week
Browse all
Salary
≈ $26k – $64k per year (Estimated)
Location
Hybrid (San José, Costa Rica)
Seniority
Middle · 3+ years exp

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Oct 1, 2026.

Overview
Company
Impact
Profile match
We build innovative, crowd-powered solutions that connect the creativity of the global security community to the global market. Our Vision A radical cybersecurity advantage. Our Values • Simple is strong • Respect is the key • Happy Customer...

Founded in 2012, Bugcrowd is the preemptive security platform that unifies exposure discovery and assessment, offensive testing, and intelligence shaped by AI and human insight to help organizations avoid, discover, and validate real-world risk. Bugcrowd helps security teams move faster by identifying the exposures that matter most so they can act first and stay ahead of attackers. By combining the power of humans and AI, teams can preempt attack paths and prevent breaches. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others. Visit www.bugcrowd.com.

Job Summary

If you like owning problems end to end, making security a default property of everything we build, and working closely with engineering, we want to meet you. Bugcrowd is looking for security engineers who move beyond standard tooling and drive measurable security outcomes our customers can rely on. You will help us shape a culture where security helps others succeed, not just points out problems.

Essential Duties and Responsibilities

  • Partner Closely with Engineering: Refine architecture, validate new features, and drive security investment while prioritizing engineering velocity
  • Build Security Paved Roads: Contribute to the secure defaults, libraries, and "paved roads" that systematically eradicate entire classes of vulnerabilities rather than fixing bugs one by one
  • Create Feedback Loops: Tune security tooling such as SAST, DAST, SCA, and secret scanning to reduce noise and focus on what matters
  • Be our Best Customer: Ensure our bug bounty program can be a model for other customers. Experiment with new ways to leverage the creativity of the crowd. Provide feedback on new platform features to engineering and product
  • Own Projects End to End: Lead cross-functional product security projects from scoping through delivery, influencing product and engineering roadmaps and clearly communicating risk to both technical and non-technical stakeholders
  • Amplify our Impact: Use code and automation as a lever to scale coverage and eliminate repetitive work. Build systems based on incentives and accountability rather than just bureaucratic process

Education, Experience, Knowledge, Skills, and Abilities

  • 3+ years of experience in product security, application security, or secure software development
  • Can review code, automate tasks, and build security tooling in at least one modern programming language (e.g., Python, Go, Ruby, Java)
  • Hands-on experience with core application security practices - threat modeling, secure code review, and automated testing (SAST, DAST, SCA) - and a solid grasp of common vulnerability classes (e.g., OWASP Top 10)  
  • Demonstrated ability to manage projects and influence cross-functional partners across engineering, DevOps, and product.
  • Bachelor's degree in engineering, computer science or relevant field, or equivalent practical experience  

Bonus Points (Preferred but not required)

  • Previous experience with Bug Bounty or vulnerability disclosure programs  
  • A background in building "paved roads" or secure-by-default internal libraries to eliminate entire classes of vulnerabilities  
  • Hands-on experience securing cloud-native platforms and Infrastructure as Code (e.g., Terraform, AWS, GCP, Kubernetes, Docker)  
  • Experience working within a fast-paced, high-growth security or SaaS company

Working Conditions and Physical Requirements

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

  • Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
  • Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
  • Environment - remote, work-from-home 100% of the time

ADA Statement: 

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at [email protected].

Additional Requirements:

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, education verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Equal Opportunity Employer:

Bugcrowd is an Equal Opportunity and Affirmative Action employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists-you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer. 

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. 

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at:  https://www.bugcrowd.com/about/careers/

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,051,596 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
San José
≈ $33k – $75k per year (Estimated) • In office • Full-Time • San José
JavaScript
DevOps
AWS
Apply
≈ $77k – $206k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Munich • Berlin
Python
Go
Java
AI/ML
AI Agents
DevOps
GCP
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
ISO 27001
OWASP Top 10
SOC 2
Threat Modeling
Apply
$94k – $165k per year • In office • Full-Time • 7+ years exp
DevOps
Windows
TCP/IP
Management
Microsoft Office
Apply
$125k – $178k per year • Remote (United States) • 6+ years exp
Python
Databases
Apache Iceberg
Delta Lake
DevOps
Terraform
GitHub Actions
AWS CDK
CloudFormation
CI/CD
Jenkins
AWS
Docker
AWS Lambda
Amazon S3
IAM
Amazon CloudWatch
AWS Step Functions
Analytics
ETL/ELT
Management
Agile
Apply
≈ $112k – $220k per year (Estimated) • Hybrid • Bachelor's Degree • Temple
AI/ML
Copilot
Cybersecurity
SIEM
Management
Agile
Apply
≈ $17k – $49k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Taguig
Python
JavaScript
TypeScript
Ruby
C++
Python
Django
DevOps
Linux
Windows
Apply
C++ Developer 7 hours ago
≈ $21k – $49k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Taguig
Python
JavaScript
TypeScript
Ruby
C++
Python
Django
DevOps
Linux
Windows
Apply
In office • Full-Time • Bachelor's Degree • Taguig
Python
DevOps
Ansible
Azure
AWS
Kubernetes
Linux
Unix
DNS
DHCP
Management
Microsoft Office
Apply
≈ $113k – $209k per year (Estimated) • Remote (United States) • Full-Time • Associate's Degree
Python
SQL
Analytics
Microsoft Excel
Apply
Data Analyst 7 hours ago
$133k – $166k per year • In office • 2+ years exp • Bachelor's Degree • New York
Python
JavaScript
SQL
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
Microsoft Fabric
BigQuery
AI/ML
LangGraph
LangChain
LlamaIndex
dbt
Copilot Studio
Frontend
Tailwind CSS
D3.js
Chart.js
React.js
Radix UI
shadcn/ui
Recharts
Plotly.js
DevOps
CI/CD
Git
Analytics
Tableau
Power BI
ETL/ELT
A/B Testing
Azure Data Factory
AWS Glue
Dimensional Modeling
Management
Power Automate
Power Apps
Apply
≈ $40k – $112k per year (Estimated) • Remote (Brazil) • Confidential • Bachelor's Degree
DevOps
Kali Linux
Linux
Cybersecurity
Burp Suite
Nmap
SQLmap
OWASP
Apply
≈ $15k – $37k per year (Estimated) • Remote (India) • Confidential • Contractor • Bachelor's Degree
DevOps
Kali Linux
Linux
Cybersecurity
Burp Suite
Nmap
SQLmap
OWASP
Apply
$176k – $243k per year • Remote (United States) • Confidential
Python
Rust
AI/ML
Reinforcement Learning
AI Agents
Cohere SDK
LLM
OpenAI
Anthropic
DevOps
GitHub Actions
Docker
Linux
Apply
$83k – $110k per year • Remote (United States) • Confidential • 3+ years exp
Apply
≈ $36k – $86k per year (Estimated) • Remote (Costa Rica) • Confidential • 2+ years exp
Python
Apply
≈ $31k – $84k per year (Estimated) • Remote (Costa Rica) • Full-Time • 5+ years exp • San José
Java
C#
C#
ASP.NET Core
MediatR
xUnit
FluentValidation
Frontend
GraphQL
Mobile
Clean Architecture
DevOps
Rest API
Azure
CI/CD
AWS
Docker
Amazon ECS
Cybersecurity
Keycloak
Management
Agile
Apply
≈ $47k – $126k per year (Estimated) • Remote (Costa Rica) • 1+ year exp • Bachelor's Degree • San José
AI/ML
AI Agents
Analytics
Tableau
Management
Smartsheet
Marketing
Salesforce
LinkedIn
Apply
≈ $14k – $35k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • San José
Management
ServiceNow
Apply
$103k – $137k per year • In office • Full-Time • 12+ years exp • Master's Degree • Los Angeles • San José
Python
SPSS
Stata
Analytics
Power BI
Apply
In office • 2+ years exp • San José
AI/ML
AI Agents
Analytics
Microsoft Excel
Apply
See all jobs
This is one of many
1,051,596 more open roles from verified company boards, updated every day.