CVE Vulnerability Expert
Commitment
40 hrs/week
Location
Remote
Availability
3 spots left
$70–90 / hr
Applying through our link may earn us a small commission — at no extra cost to you.
About this role
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback.
Basic Qualifications
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
- Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)
- Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)
- Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)
- Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications
- OSCP, GPEN, GWAPT, or equivalent offensive-security certification
- Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code
- Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling
- Prior technical content review, assessment design, or QA for security-focused engineering tasks
About Mercor
The strongest pipeline for credentialed experts. Contracts are clear, and workers report payouts landing on schedule.
Trust score 9.2/10Read our Mercor review →
Next steps
AITrainerGigs aggregates this listing from Mercor.