Application Security Engineer – CVE & Vulnerability Research
Anyone AI · 100% remote · Contract · Posted
- Pay
- $65/hr
- Location
- Latin America and Europe
- Languages
- English
- Hours
- Part-time, project-based consulting
- Openings
- Not listed
- Level
- Experienced
Summary
Review CVE reproduction environments and exploit proof-of-concepts to verify accuracy, evaluate security fixes and remediation strategies, and validate test suites for exploit mitigation and functionality.
What you'll do
- Review CVE reproduction environments for technical accuracy
- Determine whether vulnerabilities faithfully reproduce the original attack vector and impact
- Evaluate proposed security fixes and remediation strategies
- Review test suites verifying normal functionality and exploit mitigation
- Identify incomplete fixes and alternative exploitation paths
- Review Docker environments for correct software versions, services, networking, and configuration
- Detect potential regressions or new vulnerabilities introduced by a fix
- Provide recommendations for improving vulnerability reproductions, fixes, and verification logic
Requirements
- Have 3+ years of application security, penetration testing, or vulnerability research experience
- Understand CVE, CVSS, CWE, and common vulnerability classes
- Identify and remediate vulnerabilities like SQL injection, command injection, SSRF, deserialization, buffer overflows, privilege escalation, and access control issues
- Use Docker and Docker Compose
- Provide clear, technically rigorous written feedback
- Review or develop exploit proof-of-concepts
- Validate whether security fixes address root cause
- Experience with secure coding and vulnerability remediation
Skills
- Application Security
- Penetration Testing
- Vulnerability Research
- CVE
- CVSS
- CWE
- Docker
- Python
Full description
Anyone AI is recruiting experienced Application Security Engineers and Vulnerability Researchers for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.
We’re looking for security professionals with hands-on experience in penetration testing, vulnerability research, or application security who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated.
What You’ll Work On
You’ll review technical security tasks involving:
CVE vulnerability reproduction
Exploit proof-of-concepts
Vulnerability remediation and secure coding
Application security testing
Docker-based vulnerability labs
Exploit verification scripts
Security regression testing
CVSS, CWE, and vulnerability classification
Environment and configuration analysis
Edge cases and alternative attack paths
A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality.
What We’re Looking For
3+ years of hands-on experience in application security, penetration testing, or vulnerability research
Strong understanding of CVE, CVSS, CWE, and common vulnerability classes
Experience identifying and remediating vulnerabilities such as:
SQL injection
Command injection
SSRF
Deserialization vulnerabilities
Buffer overflows
Privilege escalation
Access control issues
Security misconfigurations
Strong understanding of secure coding and vulnerability remediation
Experience reviewing or developing exploit proof-of-concepts
Experience validating whether security fixes address the root cause rather than only the immediate exploit
Proficiency with Docker and Docker Compose
Ability to provide clear, technically rigorous written feedback
What You’ll Be Responsible For
Reviewing CVE reproduction environments for technical accuracy
Determining whether vulnerabilities faithfully reproduce the original attack vector and impact
Evaluating proposed security fixes and remediation strategies
Reviewing test suites that verify both:
Normal application functionality remains intact
The original exploit no longer succeeds
Identifying incomplete fixes and alternative exploitation paths
Reviewing Docker environments for correct software versions, services, networking, and configuration
Detecting potential regressions or new vulnerabilities introduced by a fix
Providing recommendations for improving vulnerability reproductions, fixes, and verification logic
Nice to Have
OSCP, GPEN, GWAPT, or equivalent security certification
Experience with responsible vulnerability disclosure or CVE reporting
Experience maintaining exploit proof-of-concept code
Experience writing automated security tests using tools such as:
Python
requests
curl
pwntools
Custom exploit harnesses
DevSecOps experience
Familiarity with SAST, DAST, and CI/CD security tooling
Experience developing or reviewing cybersecurity assessments or technical security challenges
Experience with AI evaluation, RLHF, or technical data projects
Engagement
Work Type: Remote
Engagement: Part-time, project-based consulting
Focus: Application security, vulnerability research, CVE reproduction, and remediation
This role is ideal for security engineers who enjoy understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.
Location: open to applicants in Argentina, Brazil, Chile, Colombia, Ecuador, Mexico, Portugal, Spain, Uruguay.
Similar jobs
Software Engineers: Paid Code Review for AI Agent EvaluationSoftware EngineeringTest SuitesEvaluation HarnessesCode ReviewBackend DevelopmentFull-Stack Development+7$65/hr
🌍 Worldwide
Competitive CoderBasics C++Competitive Programming+1$45–65/hr
🌍 Worldwide
AWS Trainium / NKI Kernel ExpertNKIAWS TrainiumCUDATritonNeuron SDKKernel Optimization+5$65/hr
🌍 Latin America and Europe
Senior Software Engineer – Open Source & SWE-Bench EvaluationSoftware EngineeringOpen SourceUnit TestingGitGitHubDebugging+7$65/hr
🌍 Latin America and Europe