Interactive Brokers
Financial Services
SecurityEngineer–BugBounty
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Security Engineer – Bug Bounty at Interactive Brokers. Skills: Bug bounty operations, Vulnerability validation, Developer partnership. Own bug bounty program operations. Triage reports”
Industry & Context.
Root cause analysis
What They're Looking For.
Must Have
2-5 years application security, 2-5 years penetration testing, 2-5 years bug bounty operations, 2-5 years security engineering, Foundational web application vulnerability knowledge, Ability to reason about exploitability, Experience operating bug bounty program, Written communication under pressure, Familiarity with REST API security, Familiarity with GraphQL API security, Familiarity with OAuth 2.0 flows, Familiarity with session management, Familiarity with web application architecture, Ability to work cross-functionally
Nice to Have
Active bug bounty participation, Development background, Experience in financial services, Scripting ability in Python, Scripting ability in Bash, Familiarity with DAST tooling
What You'll Do.
Own bug bounty program operations
Communicate with researchers
Make payout decisions
Maintain SLA compliance
Reproduce vulnerabilities
Validate vulnerabilities
Reason about exploitability
Distinguish genuine risk
Escalate critical issues
Act as remediation partner
Clarify findings with developers
Provide exploit context
Track remediation blockers
Identify recurring vulnerability classes
Feed patterns into AppSec
Close loop from discovery to prevention
Maintain program scope
Maintain out-of-scope guidance
Maintain rules of engagement
Adjust scope based on changes
Coordinate with legal
Coordinate with compliance
Coordinate with communications
Produce program metrics
Analyze metrics for decisions
Evaluate attack surface expansions
How You'll Work.
Team & Collaboration
Work with engineering teams; Work with developers
Communication Scope
Written communication
Full Job Description
Company Overview Interactive Brokers Group, Inc. (Nasdaq: IBKR) is a global financial services company headquartered in Greenwich, CT, USA, with offices in over 15 countries. We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technology and client commitment. IBKR affiliates provide global electronic brokerage services around the clock on stocks, options, futures, currencies, bonds, and funds to clients in over 200 countries and territories. We serve individual investors and institutions, including financial advisors, hedge funds and introducing brokers. Our advanced technology, competitive pricing, and global market help our clients to make the most of their investments. Barron's has recognized Interactive Brokers as the #1 online broker for six consecutive years. Join our dynamic, multi-national team and be a part of a company that simplifies and enhances financial opportunities using state-of-the-art technology. Security Engineer - Bug Bounty About the Role We are looking for a Security Engineer focused on Bug Bounty who treats researcher reports as security data, not support tickets. This is not a coordination role — you will be hands-on validating vulnerabilities, reproducing exploits, and working directly with engineering teams to drive fixes. You will own the full lifecycle of the program: scope design, triage, researcher relations, remediation tracking, and the upstream feedback that turns external findings into internal controls. The other half of this role is developer partnership. Findings that sit in a backlog do not improve security. You will reduce the friction that keeps confirmed vulnerabilities from being fixed — translating researcher reports into clear remediation guidance, removing ambiguity that slows engineers down, and identifying the process or tooling gaps that let the same vulnerability class appear repeatedly. A deep understanding of how vulnerabilities actually work — not just how to cl
Applying for this Security Engineer – Bug Bounty role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Interactive Brokers?
Real rants from real employees. Read before you apply.