With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?
My understanding is that the grey market for exploits is way more lucrative than the bug bounty programs.
(1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases. People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it.
(2) You are willing to get your hands dirty with shady purchasers. If you're talented, you can make good money in the grey market, or you can retain plausible deniability about what your work is being used for, but you can't do both of those things.
That first case is really the limiting factor. And remember, if you can reliably sell bugs to the grey market, that strongly implies you have lucrative options in the legitimate market. Bug bounties are not the most competitive alternative to the grey market!