Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Specialist - Fully Remote | Upto $90/hr

Mercor

Job Description

Job Description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey .

Position: CVE Vulnerability Expert
Type: Contract
Compensation: $70–$90/hour
Location: Remote

Role Responsibilities

  • Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training.
  • Assess CVE reproductions for faithfulness and ensure fixes are sound.
  • Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions.
  • Provide clear, rubric-based written feedback to improve model outputs.
  • Collaborate with AI research teams to enhance training data quality and downstream performance.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks ( CVSS , CWE , CAPEC ).
  • Demonstrated expertise in secure coding and remediation across common vulnerability classes ( SQL injection , command injection , buffer overflow , deserialization , SSRF , misconfigurations , privilege escalation ).
  • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests).
  • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Preferred

  • OSCP , GPEN , GWAPT , or equivalent offensive-security certification.
  • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code.
  • Background in DevSecOps , CI/CD security gating, or SAST/DAST tooling.
  • Prior technical content review, assessment design, or QA for security-focused engineering tasks.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Specialist - Fully Remote | Upto $90/hr. Be the first to apply!