AIPayList

Jobs / Mercor

CVE Vulnerability Expert

up to $90/hr

source wording: “70–90 USD HOUR

Platform
Mercor
Category
Other AI work
Eligibility
Worldwide
Freshness
posted 17h ago · seen live 1h ago

What this role asks for

  • 3+ yrs experience
  • SQL
Read from the posting's own words: show the exact sentences
  • 3+ yrs experience: “…clear, rubric-based written feedback. Basic Qualifications • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong…
  • SQL: “…secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations,…

The role, as Mercor describes it

Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback.

Basic Qualifications

• 3+ years of hands-on experience in application security, penetration testing, or vulnerability research

• Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)

Read the rest of the description (8 more paragraphs)

• Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)

• Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)

• Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments

Preferred Qualifications

• OSCP, GPEN, GWAPT, or equivalent offensive-security certification

• Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code

• Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling

• Prior technical content review, assessment design, or QA for security-focused engineering tasks

Posted by Mercor, reproduced here so you can judge the role before clicking. Original posting ↗

Source: platform job feed · first seen 1h ago · ID list_AAABoDrLTtVzOBh5