Skip to content
Jobsearch.ing

Bug Bounty Security Researcher

JobgetherRemote · AU

Contract1+ yrs
Source-verified: read directly from this employer's own lever job board, not a repost.RemotePosted (3 days ago)Last verified (today)

At a glance

Location
Remote · AU
Workplace
Remote
Pay
Not published by the employer
Employment type
Contract
Experience
1+ years
Education
No degree requirement stated
Job family
Not classified
Seniority
Not stated
Posted by employer
4 September 2026
Last verified open
7 September 2026
Work from
AU
Region and country
AU
Team
Security & IT
Listed via
Lever

What the employer wrote

Accountabilities • Conduct thorough security research across target applications, systems, and networks to identify vulnerabilities and potential attack paths.

• Develop and execute customized attack vectors using techniques such as fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Remote Code Execution.

• Safely validate and exploit discovered vulnerabilities while following responsible testing and disclosure practices.

• Analyze application and infrastructure behavior to identify weaknesses that may not be apparent through standard automated testing.

• Produce clear and comprehensive vulnerability reports containing technical descriptions, proof-of-concept code or evidence, severity information, and reproducible steps.

• Participate in ongoing bug bounty programs and private security research engagements.

• Share security findings and insights that can help improve products, services, and overall vulnerability management practices.

• Continuously research new attack techniques, tools, vulnerabilities, and security trends to improve testing effectiveness.

• Contribute to a collaborative security environment focused on identifying and responsibly addressing real-world threats.

Requirements

• At least 1 year of professional or demonstrable experience in security research, penetration testing, vulnerability assessment, or a related field.

• Strong understanding of computer systems, networks, web applications, and software security.

• Practical knowledge of offensive security methodologies and vulnerability discovery techniques.

• Experience with programming or scripting languages such as Python, C++, JavaScript, and HTML.

• Familiarity with security tools including Burp Suite, OWASP ZAP, Nmap, and Kali Linux.

• Experience participating in bug bounty programs and applying responsible disclosure practices.

• Strong analytical, investigative, and problem-solving abilities.

• Excellent technical communication and documentation skills, with the ability to clearly explain complex vulnerabilities.

• Relevant application security certifications such as Burp Suite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), or Offensive Security Certified Professional (OSCP) are highly valued.

• 3+ years of experience in security research, penetration testing, or vulnerability assessment is a strong advantage.

• A recognized public bug bounty profile with awarded vulnerability reports is preferred.

• Recognized contributions to Common Vulnerabilities and Exposures (CVEs) are a plus.

• Strong sense of responsibility and commitment to ethical security research.

Benefits

• Flexible freelance engagement allowing you to work according to your own schedule.

• Bounty awards for valid and accepted vulnerability reports.

• Weekly payments for valid reports following successful triage.

• Recognition for high-quality submissions through leaderboards both on and outside the platform.

• Opportunities to perform real-world penetration testing across web application, mobile, and network security.

• Access to private and exclusive bug bounty programs.

• Opportunity to work on diverse targets and investigate high-impact security vulnerabilities.

• Collaborative, empathy-led security culture focused on improving internet security.

• Continuous exposure to modern offensive security techniques, tools, and emerging vulnerabilities.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1

Where this record came from

Read from Jobgether's own Lever job board on , and last confirmed still open on . The employer published it on 4 September 2026. Jobsearch.ing did not write, edit or rank this posting, and does not vet the employer. View the original posting.

More roles like this one