390,676open jobs
10,358companies
50,329added this week
Browse all
Salary
$36k – $94k per year (Estimated)
Location
Remote (Mexico)
Seniority
Middle · 3+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Bug Bounty Security Researcher based in Mexico.

This is an exciting security research opportunity for a skilled professional passionate about discovering vulnerabilities and strengthening real-world application security.

You will investigate software applications, systems, and networks to uncover security weaknesses before they can be exploited maliciously.

The role combines offensive security research, creative attack development, vulnerability exploitation, and detailed technical reporting.

You will work across web, mobile, and network security environments while participating in private and public bug bounty programs.

Your findings will directly contribute to improving security products and services and protecting customers against emerging threats.

The position offers flexibility to work independently, explore challenging targets, and be rewarded for high-impact vulnerabilities.

This opportunity is ideal for a curious and analytical security researcher who enjoys continuous learning and responsible vulnerability disclosure.

Accountabilities

    • Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.
    • Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.
    • Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.
    • Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.
    • Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.
    • Participate in ongoing bug bounty programs and private security research engagements.
    • Share security findings and insights that can help improve products, services, and overall vulnerability management practices.
    • Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.
    • Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.
    • Requirements

      • At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.
      • Strong understanding of computer systems, networks, web applications, and software security.
      • Practical knowledge of offensive security methodologies and vulnerability discovery techniques.
      • Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.
      • Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.
      • Experience participating in bug bounty programs and applying responsible disclosure practices.
      • Strong analytical, investigative, and problem-solving abilities.
      • Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.
      • Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.
      • 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.
      • A recognized public bug bounty profile with awarded vulnerability reports is preferred.
      • Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.
      • Strong sense of responsibility and commitment to ethical security research.
      • Benefits

        • Flexible freelance engagement allowing you to work according to your own schedule.
        • Bounty awards for valid and accepted vulnerability reports.
        • Weekly payments for valid reports following successful triage.
        • Recognition for high-quality submissions through leaderboards both on and outside the platform.
        • Opportunities to perform real-world penetration testing across web application, mobile, and network security.
        • Access to private and exclusive bug bounty programs.
        • Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.
        • Collaborative, empathy-led security culture focused on improving internet security.
        • Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
390,676 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$22k – $61k per year (Estimated) • In office • 6+ years exp • Bengaluru
C++
Go
Java
Node JS
Python
Rust
JavaScript
DevOps
Kubernetes
Apply
QA Tester 1 day ago
$9k – $36k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Bengaluru
JavaScript
Python
SQL
DevOps
CI/CD
GitHub
GitHub Actions
GitLab
GitLab CI
Jenkins
Rest API
Management
Jira
QA
Cypress
JMeter
k6
Playwright
Postman
Pytest
Rest-Assured
Selenium
Apply
$31k – $55k per year (Estimated) • Remote • 5+ years exp • Moscow
C#
JavaScript
C#
ASP.NET Core
Frontend
Vue.js
DevOps
GitLab
Kubernetes
Apply
$38k – $123k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Berlin
JavaScript
TypeScript
Frontend
Angular
JQuery
React.js
Marketing
LinkedIn
Apply
$21k per year (net) • Remote • 3+ years exp • Moscow
JavaScript
PHP
PHP
Bitrix
Databases
MySQL
DevOps
Git
Rest API
Management
Bitrix24
Apply
$111k – $167k per year • Equity • Remote • Full-Time • 5+ years exp
Cybersecurity
FedRAMP
ISO 27001
NIST CSF
SOC 2
Management
ServiceNow
Apply
$77k – $101k per year • Remote • Full-Time • 2+ years exp • Bachelor's Degree
Bash
Python
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
NIST CSF
Nmap
Threat Modeling
Apply
$111k – $189k per year (Estimated) • Remote • Full-Time • 6+ years exp • Bachelor's Degree
Apply
$125k – $225k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
DevOps
Debian
Ubuntu
Apply
$25k – $60k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
DevOps
Debian
Ubuntu
Apply
See all jobs
This is one of many
390,676 more open roles from verified company boards, updated every day.