CVE Vulnerability Expert
Mercor · 100% remote · Contract · Posted
- Pay
- $70–90/hr
- Location
- United States
- Languages
- English
- Hours
- Flexible
- Openings
- Not listed
- Level
- Expert
Summary
Evaluate quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI training. Assess CVE reproductions, fix soundness, verification logic, and Docker environments, and provide rubric-based feedback.
What you'll do
- Assess CVE reproductions for fidelity
- Evaluate remediation soundness
- Check verification logic rigor
- Review Docker-based lab environments for accurate exploitability
- Provide clear rubric-based written feedback
Requirements
- Have 3+ years of experience in application security, penetration testing, or vulnerability research
- Understand CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)
- Demonstrate expertise in secure coding and remediation across common vulnerability classes
- Design or evaluate two-part verification logic (functionality and vulnerability tests)
- Use Docker and Docker Compose for multi-container environments
Skills
- CVE
- CVSS
- CWE
- CAPEC
- Docker
- Docker Compose
- Penetration Testing
- Secure Coding
Full description
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback.
Basic Qualifications • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC) • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation) • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests) • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications • OSCP, GPEN, GWAPT, or equivalent offensive-security certification • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code • Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling • Prior technical content review, assessment design, or QA for security-focused engineering tasks
Location: open to applicants in United States.
Similar jobs
Staff Software Engineer, Mobile (Android, Kotlin, Full Stack)AndroidKotlinJetpackiOS/SwiftBackend ServicesAPIs+5$50–90/hr
🇺🇸 US
Machine Learning Engineers: Scenario Building for Reinforcement LearningReinforcement LearningSimulation DesignRL FrameworksScenario BuildingPlatform Interfaces+4$90/hr
🌍 Worldwide
AI Developer Trace Task AuditorCursorGitHub CopilotClaude CodeDebuggingFull-Stack DevelopmentBackend Systems+6$70–90/hr
🇺🇸 US
SWE-Bench Task AuditorPythonJavaGoTypeScriptC++SWE-Bench+5$70–90/hr
🇺🇸 US