Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Mercor · 100% remote · Contract · Posted
- Pay
- $200–250/hr
- Location
- Worldwide
- Languages
- English
- Hours
- Flexible
- Openings
- Not listed
- Level
- Expert
Summary
Evaluate AI-generated cybersecurity analyses, review vulnerability reports and technical writeups, validate root-cause analysis, and provide structured feedback on exploit chains and defensive recommendations. Contribute to benchmark development for AI security capabilities.
What you'll do
- Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
- Review technical writeups for correctness, exploitability, and mitigation quality.
- Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
- Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
- Contribute to benchmark development for advanced AI security capabilities.
Requirements
- Member of a top-ranked CTF team with demonstrated competitive achievements.
- Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
- Publicly recognized bug bounty researcher with findings accepted by major programs.
- Research experience at a respected security laboratory or academic research group.
- Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research.
- Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
- Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
- Strong programming skills in C/C++, Rust, Python, Go, or Java.
Skills
- Exploit Development
- Reverse Engineering
- Vulnerability Research
- Binary Analysis
- C/C++
- Python
- IDA Pro
- Fuzzing
Full description
We're looking for highly accomplished Cybersecurity Research Experts to help evaluate cutting-edge AI systems in advanced security reasoning, vulnerability analysis, exploit development, and secure software engineering. This project is ideal for practitioners with a strong track record in offensive security research and publicly recognised technical contributions.
What You'll Do
Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
Review technical writeups for correctness, exploitability, and mitigation quality.
Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
Contribute to benchmark development for advanced AI security capabilities.
Ideal Background
We are looking for candidates with multiple of the following credentials:
Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
Research experience at a well-respected security laboratory or academic research group (e.g., KAIST Security Lab, SSLab, university security research groups, or equivalent industry research organisations).
Author of high-quality security research publications, conference papers, or widely cited technical writeups.
Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred Qualifications
Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
Strong programming skills in C/C++, Rust, Python, Go, or Java.
Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
Hall of Fame recognition from major bug bounty programs.
Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
Maintainer or significant contributor to well-known open-source security tools.
Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Why Join?
Work on frontier AI models tackling real-world cybersecurity problems.
Collaborate with leading researchers on advanced security evaluation tasks.
Help shape the next generation of AI systems for cybersecurity.
Similar jobs
Software Developers: Share Your AI Coding SessionsNewAI Coding ToolsTerminalGitOpenCodeGemini Models+3$100–250/hr
🌍 Worldwide
Machine Learning Engineer Talent NetworkMachine LearningPythonPyTorchTensorFlowMLOpsModel Deployment+4$70–250/hr
🌍 Worldwide
Senior Software EngineerSystem DesignCode ReviewDebuggingAlgorithmsData StructuresSoftware Architecture+4$245–280/hr
🌍 English-speaking countries
Data ScientistPythonMachine LearningStatisticsData AnalysisExperimentationPandas+5$245–280/hr
🌍 English-speaking countries