--- title: 'Software Engineer at Bug Bounty Switzerland' canonical: 'https://feeny.ai/job/software-engineer-bug-bounty-switzerland-zurich-dkvg5d3gcfas' type: 'job' last_seen: '2026-09-11' --- # Software Engineer at Bug Bounty Switzerland - **Company:** Bug Bounty Switzerland - **Location:** Zürich, Switzerland / Bern, Switzerland - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-02-24 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/bug-bounty-switzerland/c712a9c3-d5cf-492b-ba1f-870bacc61aa3 ## Job description ## About SignalFisher SignalFisher is the leading Security Testing Hyperscaler. With our Cyber Resilience Platform, we help regulated enterprises in financial services, critical infrastructure, and government stay ahead of evolving threats. We’re headquartered in Switzerland, trusted by some of the most security-conscious organisations in Europe, and scaling fast. ## The Role We're building the operating system for enterprise security testing - a platform that turns security objectives into executable plans and translates findings into actionable insights. We have a proven orchestration engine, a growing AI layer, and real customer traction. Now we need a Software Engineer to build and scale the backend systems that bring them together. You'll own the services, data layer, and integration points that power the platform end-to-end, architect the systems where agents, humans, and code interact, and ship what customers rely on daily. This is a senior role with high autonomy, clear accountability, and the space to create real impact. ## What You'll Do Build & Scale the Platform That Powers Security Testing You'll design, build, and maintain the backend systems that make our security testing platform reliable, fast, and extensible. This means: - Architecting and evolving backend services in C# / .NET Core and Python that form the backbone of our platform - Building and maintaining APIs and integration points (REST, MCP) that connect our orchestration engine, AI capabilities, and customer-facing interfaces - Designing granular identity and access control across human users, AI agents, and service-to-service calls - Working across a multi-model data layer (Azure SQL, CosmosDB document + graph) - designing storage and data flows that fit the access pattern, serving both deterministic logic and AI agents - Architecting systems where agents, humans, and deterministic logic co-drive security testing - event-driven choreography and durable execution patterns that trigger, await, and react to each other across long-running, stateful workflows - Deploying and operating services across Azure compute (Kubernetes, Functions, Container Apps) with a focus on reliability, scalability, and security - Co-creating internal admin interfaces on Retool, to streamline operations - Contributing to our Angular frontend when needed - fixing issues end-to-end rather than stopping at the API boundary Own Your Impact End-to-End You'll work in cross-functional teams with full domain ownership - where success means moving the needle for customers and the business: - Drive projects from shaped bets with clear appetite and boundaries - find the best way to deliver them with your team, in pairs, or independently - Navigate ambiguity with confidence - make smart trade-offs, prototype when needed, and ship what matters - Partner with peers, product, and stakeholders to solve customer security challenges through technical innovation - Balance speed with craft - build on a strong, well-maintained core with the discipline needed for production-grade systems - Leverage AI developer tools (Copilot, Claude Code, etc.) as a natural part of your workflow to accelerate delivery - Ship meaningful contributions within your first weeks, then take on increasingly complex challenges ## What You Bring Must-haves - 7+ years of professional software engineering experience with a track record of shipping and maintaining production systems - Strong proficiency in C# and .NET Core - Experience with large-scale Python software development - Experience designing and operating services on Azure or comparable cloud platforms - Understanding of event-driven architectures and messaging (Azure ServiceBus, RabbitMQ, or similar), ideally with frameworks like MassTransit - Depth in relational and non-relational databases, including hands-on experience with ORMs like Entity Framework - Experience deploying and operating containerized workloads across cloud compute models (Kubernetes, Functions, Container Apps) - Strong software engineering fundamentals: you write code that is testable, maintainable, and built for production - Proven skills in structured, independent problem-solving - comfortable working with incomplete information and rapidly testing hypotheses - Proactive in leveraging AI developer tools (GitHub Copilot, Claude Code, or similar) in your daily workflow - A thoughtful communicator who values clarity, simplicity, and direct feedback - Comfortable working in-office on a hybrid schedule (Zurich/Bern) - we believe the best engineering happens when the core team can whiteboard, pair, and align in person - Language requirements: English required; German a plus Strong signals - Experience with hybrid architecture patterns - combining event-driven choreography and orchestrated execution across long-running, stateful, human-in-the-loop workflows - Experience with graph databases or multi-model databases (e.g., CosmosDB with both document and Gremlin APIs) - Familiarity with LLMs in production: building around agentic frameworks, prompt engineering, or integrating AI capabilities into backend systems - Familiarity with real-time communication patterns (SignalR, SSE, WebSockets) - Depth with Azure services beyond compute and data (e.g. Key Vault, Blob Storage, Application Insights) - Experience with durable execution and long-running workflows (Durable Functions, Prefect, Temporal) - Familiarity with modern observability practices: structured logging, metrics, and distributed tracing across services - Frontend experience with Angular and TypeScript - Experience building low-code admin tooling (Retool or similar) - Prior experience in cybersecurity, security testing, or building products for technical/security-focused users - Experience in a growth-stage startup and comfort with ambiguity - Familiarity with CI/CD pipelines, infrastructure as code (Bicep, Terraform), and DevOps practices Reporting & Compensation - Reports to: CTO - Compensation: Competitive base + ESOP, aligned with seniority and impact - Work setup: Hybrid (Zurich/Bern) - regular in-office presence expected - Employment type: Full-time ## Why This Role We've built a security testing platform with a working orchestration engine, a growing AI layer, and enterprise customers relying on it daily. The pieces are in place - now we need the backend engineering depth to scale what's working and build what's next: systems where agents, humans, and deterministic logic don't just coexist but co-drive security testing workflows end-to-end. This role has leverage because our platform's intelligence is only as strong as the systems that power it. You'll build the interfaces that connect orchestration to action, the data layer that serves both code and agents, and the execution patterns where all three interact across long-running, stateful workflows. You'll do this in cross-functional teams with full domain ownership - where your decisions directly shape what customers experience. If you want ownership, accountability, and the kind of impact that comes from building the backbone of an AI-native security platform - this is the role. ## About Bug Bounty Switzerland ## Company Overview - **One-liner**: Bug Bounty Switzerland provides an AI-powered, data-driven security testing platform (Cyber Resilience Shield) that enables enterprises to perform continuous, scalable, and compliant security assessments. - **Entity Type**: Private (Series A, raised USD 15.2M in 2026) - **Headquarters**: Zürich, Switzerland (with offices in Lucerne and Bern) - **Founded**: 2020 - **Founders**: Sandro Nafzger (CEO), Florian Badertscher (COO), Lukas Heppler (CTO) ## Core Business - **Primary industry**: Computer and Network Security / Cybersecurity - **Target customers**: Enterprise B2B (organizations needing continuous security testing, vulnerability management, and compliance with regulations like NIS2 and the EU Cyber Resilience Act) - **Mission or purpose**: Reshape security testing – faster, smarter, more resilient. To enable companies to perform continuous, scalable, and easily accessible security assessments – always-on, plug-and-play. ## Products & Services - **[Cyber Resilience Shield](https://cyberresilienceshield.com/)**: An enterprise-grade SaaS platform that orchestrates the full security test lifecycle. It maintains a "living digital twin" of a company's attack surface, combines human ethical hackers with AI agents, and streams results into an interpretable resilience picture. Key features include geo-redundant hosting with Swiss data residency, tenant-level encryption, SSO, granular RBAC, a REST API, and auditable logs. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: Total Funding of USD 15,198,600 (Series A closed 2026-04-01, led by Deutsche Beteiligungs and Direttissima Growth Partners) - **Notable Investors/Partners**: Deutsche Beteiligungs, Direttissima Growth Partners. Advisory board includes executives from Swiss Post, PwC Switzerland, ETH Zurich, SIX Digital Exchange, and Cyverse Capital. - **Growth Signals**: Headcount has grown 47.1% year-over-year (from 20 to 36 employees). The company operates in 9 countries including India, Egypt, UAE, and Morocco. It is positioned as the "Swiss Market Leader for Ethical Hacking" with a strong focus on compliance-driven demand from NIS2 and the EU Cyber Resilience Act. ## Competitive Advantages - **Swiss Data Residency & Compliance**: Data is stored exclusively in Switzerland with per-tenant encryption and strict role-based control, a key differentiator for European enterprises with strict data sovereignty requirements. - **Combined Human + AI Testing**: Orchestrates both human ethical hackers and AI agents in a single platform, creating a "closed security testing loop" that adapts to a changing attack surface within 24 hours. - **Outcome-Based, Self-Learning Model**: The platform improves with every testing cycle, uncovering critical vulnerabilities that fragmented tooling might miss. - **Swiss Market Leadership**: First-mover advantage and dominant position in the Swiss bug bounty and security testing market, with strong local credibility. ## Strategic Focus - **Regulatory Compliance**: Capitalizing on the surge in regulatory pressure (NIS2, EU Cyber Resilience Act) which mandates structured vulnerability handling and disclosure, driving demand for verifiable, continuous testing. - **International Expansion**: Growing from a Swiss base into broader European and Middle Eastern markets (notably UAE, Egypt). - **Platform Evolution**: Moving toward more autonomous, self-learning security testing to reduce the need for in-house security specialists. - **Talent Growth**: Actively hiring across engineering, AI, product management, and enterprise sales to scale the platform and customer base. ## Why Work Here - **Culture & Principles**: The company emphasizes proactivity, positivity, growth, and clarity. They describe their workplace as "an inspiring place where we meet, work together on ambitious plans and have fun together." - **Flexible Working**: "Work where and when it suits you best" with a collaborative, flexible approach and modern tools. - **Learning & Development Budget**: CHF 4,000 per year per employee to equip yourself with everything needed to enjoy work. - **Team Events**: Regular adventures like snowboarding in Zermatt, wakeboarding on Lake Thun, or go-karting on the race track. - **Office Presence**: Based in Zürich (The Circle at Zurich Airport), with additional hubs in Lucerne and Bern. The team is international, with employees across 9 countries. - **Engineering Culture**: Building ambitious, cutting-edge security technology (AI, digital twins, autonomous testing) with a team that includes talent from Bugcrowd, HackerOne, Swisscom, CERN, and Salesforce. ## Sources 1. [cyberresilienceshield.com](https://cyberresilienceshield.com/) 2. [cyberresilienceshield.com/careers](https://cyberresilienceshield.com/careers) 3. [cyberresilienceshield.com/company](https://cyberresilienceshield.com/company) 4. [linkedin.com/company/bugbounty-switzerland](https://www.linkedin.com/company/bugbounty-switzerland/) 5. [cyberresilienceshield.com/imprint](https://cyberresilienceshield.com/imprint) ## Other roles at Bug Bounty Switzerland - [Applied AI Engineer](https://feeny.ai/job/applied-ai-engineer-bug-bounty-switzerland-zurich-1s5vr1016k2x) — Zürich, Switzerland / Bern, Switzerland - [Software Engineer](https://feeny.ai/job/software-engineer-trace3-colorado-springs-dcdm25jsktt8) — Colorado Springs, CO - [Software Engineer](https://feeny.ai/job/software-engineer-snowflake-warsaw-rk93stde6gfz) — Warsaw, Poland - [Software Engineer](https://feeny.ai/job/software-engineer-maxima-san-mateo-xmed41sy1ba8) — San Mateo, CA - [Software Engineer](https://feeny.ai/job/software-engineer-mintmcp-san-francisco-gnsz7a877qxh) — San Francisco, CA - [Software Engineer](https://feeny.ai/job/software-engineer-semperis-dallas-tk9ertgkypgk) — Dallas, TX - [Software Engineer](https://feeny.ai/job/software-engineer-at-bay-tel-aviv-gw8683vjv7w1) — Tel Aviv, Israel - [Software Engineer](https://feeny.ai/job/software-engineer-sauce-labs-inc-gurgaon-tcsf29j51c9n) — Gurgaon, India - [Software Engineer](https://feeny.ai/job/software-engineer-envoy-global-inc-hyderabad-5xsr7revgv3b) — Hyderabad, India - [Software Engineer](https://feeny.ai/job/software-engineer-encompass-technologies-melbourne-thajaqz70e1k) — Melbourne, Australia