Synack (Synack Red Team)

Synack operates the Synack Red Team (SRT), a highly vetted private network of 1,500+ penetration testers who are paid for validated vulnerabilities (typically $500 to several thousand dollars each), m

Quick facts

Synack (Synack Red Team) quick facts
FactDetail
CategoryWebsites, Games & App Testing
Platform typeBug bounty platform
Websitesynack.com
Pay unitPer task, Hourly or project rate
Payout cadenceAfter validation
Minimum ageAdult (18+) implied — legal-name contracting, ID/background check, 1099/W-8BEN tax forms; explicit minimum age UNVERIFIED
Countries15 tracked — Global — applicants from anywhere except US-sanctioned or trade-restricted countries/regions; featured researchers based in Switzerland, India, US; hacking possible 'from anywhere in the world' via virtualized workspaces.
Languagesen
EquipmentComputer, Stable internet
Experience neededExpert
Identity verificationApplication must use legal name with verifiable certifications/CVEs/social profiles; mandatory ID verification and criminal background check (significant computer-crime history disqualifies); US members file 1099, non-US file W-8BEN; strict NDAs prohibit disclosing findings or client names.
Last verified2026-09-07

In one paragraph

Synack (Synack Red Team) pays for penetration testing — billed per task, paid via methods it publishes on signup. Available: widely available. Minimum age Adult (18+) implied — legal-name contracting, ID/background check, 1099/W-8BEN tax forms; explicit minimum age UNVERIFIED.

Visit Synack (Synack Red Team)

Pros & cons — facts only

Pros

  • Available in 15 tracked countries.

Cons

  • Minimum payout not published — verify before your first cash-out.
  • Entry gated by qualification/identity checks.

How to join Synack (Synack Red Team)

  1. Apply via the official SRT job posting (job-boards.greenhouse.io/synacksrt/jobs/150860, linked from synack.com/red-team; the srt.synack.com portal exists but was unreachable during research). Five-step vetting: resume review, technical assessment, background and ID verification, behavioral interview, onboarding and training. Priority Pathways (certifications like OSCP) can bypass resume/waitlist/technical reviews; standard SRT member referrals also help. Expect a selective, slow process — weeks to months.

Signup involves: Portfolio or resume · Skills assessment · Assessment interview · Identity verification · Interview · Approval or waitlist · Waitlist possible · Project matching

Requirements

Minimum age
Adult (18+) implied — legal-name contracting, ID/background check, 1099/W-8BEN tax forms; explicit minimum age UNVERIFIED
Languages
English
Identity verification
Application must use legal name with verifiable certifications/CVEs/social profiles; mandatory ID verification and criminal background check (significant computer-crime history disqualifies); US members file 1099, non-US file W-8BEN; strict NDAs prohibit disclosing findings or client names.
Skills
Expert-level penetration testing across web apps, APIs, networks, cloud, mobile (iOS/Android), OSINT, Web3/K8s, and AI/LLM targets; must pass a practical technical assessment (time-pressured, applied skills); third-party certifications (OSCP, OSWE, OSEP, OSCE3, CPTS, CWEE, BSCP, GIAC/GXPN, CREST CCT, etc.) via 'Pathways' expedite onboarding; minimum annual productivity requirements to stay active.
Equipment
Computer and internet access; Synack provides virtualized workspaces and a researcher portal (target alerts, recon assistance, report tracking, duplicate visibility) — members hack from anywhere; a professional pentesting toolchain is expected.

Where it's available

Global — applicants from anywhere except US-sanctioned or trade-restricted countries/regions; featured researchers based in Switzerland, India, US; hacking possible 'from anywhere in the world' via virtualized workspaces.

Restrictions: Officially excluded: residents of countries/regions under US export sanctions, payment, or trade restrictions — Cuba, North Korea, Syria, Iran, Crimea, China, and Russia. Applicants may not be employees/contractors of other crowdsourced security or bug bounty companies.

  • Australia
  • Brazil
  • Canada
  • Germany
  • Egypt
  • France
  • United Kingdom
  • India
  • Mexico
  • New Zealand
  • Philippines
  • Pakistan
  • United States
  • Vietnam
  • South Africa

What kind of work

  • Penetration testing

Testing prerequisites

  • Bug reporting

Synack (Synack Red Team) FAQ

Is Synack (Synack Red Team) legit?

Yes — Synack (Synack Red Team) is a real, operating platform. We verified its signup, payout, and policy pages directly on 2026-09-07 using 6 sources.

Who can join Synack (Synack Red Team)?

Minimum age Adult (18+) implied — legal-name contracting, ID/background check, 1099/W-8BEN tax forms; explicit minimum age UNVERIFIED. Global — applicants from anywhere except US-sanctioned or trade-restricted countries/regions; featured researchers based in Switzerland, India, US; hacking possible 'from anywhere in the world' via virtualized workspaces. Application must use legal name with verifiable certifications/CVEs/social profiles; mandatory ID verification and criminal background check (significant computer-crime history disqualifies); US members file 1099, non-US file W-8BEN; strict NDAs prohibit disclosing findings or client names.

How do I sign up for Synack (Synack Red Team)?

Apply via the official SRT job posting (job-boards.greenhouse.io/synacksrt/jobs/150860, linked from synack.com/red-team; the srt.synack.com portal exists but was unreachable during research). Five-step vetting: resume review, technical assessment, background and ID verification, behavioral interview, onboarding and training. Priority Pathways (certifications like OSCP) can bypass resume/waitlist/technical reviews; standard SRT member referrals also help. Expect a selective, slow process — weeks to months.

What skills does Synack (Synack Red Team) require?

Expert-level penetration testing across web apps, APIs, networks, cloud, mobile (iOS/Android), OSINT, Web3/K8s, and AI/LLM targets; must pass a practical technical assessment (time-pressured, applied skills); third-party certifications (OSCP, OSWE, OSEP, OSCE3, CPTS, CWEE, BSCP, GIAC/GXPN, CREST CCT, etc.) via 'Pathways' expedite onboarding; minimum annual productivity requirements to stay active.

Sources & verification

Facts on this page were verified against 6 sources. Last full check: .

Visit Synack (Synack Red Team)