What I learned From Managing a Bug Bounty Program

One of main responsibilities is managing bug bounty. On paper, the workflow looks simple:

  • I triage the security issue
  • Respond to the reporter
  • Log the report into the internal ticketing system, inform engineering team
  • Prioritize the issue
  • Track the ticket.

All those activities involve technical knowledge, judgement and stakeholder management.

For every report I have to decide whether the issue is valid or duplicate. If it’s valid, I have to judge severity: critical, high, medium, low.

The researcher payout depends on my severity judgment. So, I need to be careful and double-check before deciding since it directly affects our budget.

When checking the report, I have multiple things that I need to manage: