CVE Vulnerability Expert
CVE Vulnerability Expert
- Pay
- $70 – $90/hr
- Location
- Remote — Worldwide
- Open to applicants in United States.
- Engagement
- Contractor · full time
Earns 25 points on this device — once per role per day
Applications are handled by Mercor on their own site. Dealuxe is not the employer and does not screen applicants.
The Intersection of Offensive Security and Frontier Artificial Intelligence
The cybersecurity landscape has reached an unprecedented turning point. As artificial intelligence models advance from basic text generators into sophisticated autonomous agents capable of writing code, analyzing systems, and executing logical reasoning, the technology industry faces a critical imperative: ensuring that these frontier models understand application security, vulnerability management, and remediation as deeply as human security engineers do.
Historically, career paths for penetration testers, security researchers, and application security (AppSec) specialists have centered around consulting firms, red teams, enterprise security operations centers (SOCs), or bug bounty platforms. Today, an elite tier of specialized remote opportunities has emerged, allowing seasoned security professionals to monetize their deep vulnerability research expertise by training and refining the next generation of artificial intelligence systems. Positions like the CVE Vulnerability Expert role on Mercor represent the pinnacle of this movement, offering highly competitive hourly rates between $70 and $90 for analytical work that shapes secure AI architecture.
Comprehensive Job Description & Core Responsibilities
For offensive security professionals, penetration testers, and vulnerability analysts seeking high-yield remote engagements, understanding the scope of this role is key to delivering elite results. As a CVE Vulnerability Expert, your primary mission is to evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks utilized by frontier AI laboratories.
Key Responsibilities:
- Reproduction Fidelity Assessment: Critically assess whether CVE reproductions are authentic and accurate, ensuring that simulated exploits mirror real-world threat vectors precisely.
- Remediation Soundness Auditing: Evaluate code fixes to ensure they completely eliminate root vulnerabilities without introducing regressions or secondary security flaws.
- Verification Logic Rigor: Review two-part verification logic, ensuring that functionality tests and vulnerability tests work seamlessly in tandem to prove code security.
- Container Environment Validation: Verify that Docker and Docker Compose multi-container lab environments accurately replicate vulnerable conditions in a controlled, isolated sandbox.
- Rubric-Based Feedback: Deliver clear, structured, and actionable written feedback to calibrate and guide AI model outputs.
Candidate Requirements: Qualifications & Expertise
Because these engagements directly influence the safety, robustness, and security posture of frontier AI models deployed across enterprise environments, the qualification criteria are rigorous.
- Professional Tenure: 3+ years of hands-on experience in application security, penetration testing, or offensive vulnerability research.
- Taxonomy Mastery: Strong, practical understanding of CVE vulnerability taxonomy and leading severity frameworks including CVSS, CWE, and CAPEC.
- Secure Coding & Remediation: Demonstrated expertise across common vulnerability classes such as SQL injection, command injection, buffer overflows, deserialization flaws, Server-Side Request Forgery (SSRF), security misconfigurations, and privilege escalation.
- Verification Engineering: Experience in designing or evaluating two-part verification logic combining functional testing with vulnerability validation.
- Containerization Proficiency: Strong command of Docker and Docker Compose for setting up multi-container reproduction environments.
Preferred Qualifications (Nice-to-Have): Offensive security certifications such as OSCP, GPEN, or GWAPT; direct experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept (PoC) code; background in DevSecOps, CI/CD pipeline security gating, or static/dynamic analysis (SAST/DAST) tooling.
Contract Terms, Flexibility, and Global Payout Infrastructure
The modern security expert demands professional autonomy, flexible hours, and transparent compensation structures. Mercor’s independent contractor framework is built specifically around these principles:
- Total Schedule Freedom: Complete your evaluation assignments entirely on your own schedule within a fully remote working model based in the United States (note: H1-B and STEM OPT visa sponsorships are not supported for this track).
- Dynamic Project Adaptation: Projects flex and scale according to research milestones, granting you the versatility to balance contracting with advisory work, bug bounties, or full-time responsibilities.
- Reliable Weekly Compensation: Enjoy dependable weekly payouts via globally trusted financial rails like Stripe and Wise, ensuring prompt settlement for all rendered services.
Maximizing Your Cybersecurity Expertise in the Age of AI
For years, your value as a security professional has been measured by your ability to discover flaws, break systems before malicious actors do, and write bulletproof patches. Transitioning into AI evaluation allows you to scale your impact exponentially. Instead of auditing a single application or codebase, your expert feedback helps train models that will audit millions of lines of code worldwide.
Furthermore, working closely with top-tier AI researchers keeps your technical edge razor-sharp. You remain at the bleeding edge of software vulnerability research, automated code analysis, and secure software development lifecycles—all while earning a premier rate of $70 to $90 per hour.
Take the Next Step in Your AppSec Career
Specialized roles at the intersection of offensive security and artificial intelligence attract immense interest from top-tier talent, and early applicant positions fill quickly. If you possess a deep background in vulnerability research, penetration testing, and secure coding, now is the ideal moment to secure your placement.
What the work is
- Reproduction Fidelity Assessment: Critically assess whether CVE reproductions are authentic and accurate, ensuring that simulated exploits mirror real-world threat vectors precisely.
- Remediation Soundness Auditing: Evaluate code fixes to ensure they completely eliminate root vulnerabilities without introducing regressions or secondary security flaws.
- Verification Logic Rigor: Review two-part verification logic, ensuring that functionality tests and vulnerability tests work seamlessly in tandem to prove code security.
- Container Environment Validation: Verify that Docker and Docker Compose multi-container lab environments accurately replicate vulnerable conditions in a controlled, isolated sandbox.
- Rubric-Based Feedback: Deliver clear, structured, and actionable written feedback to calibrate and guide AI model outputs.
What they ask for
- Professional Tenure: 3+ years of hands-on experience in application security, penetration testing, or offensive vulnerability research.
- Taxonomy Mastery: Strong, practical understanding of CVE vulnerability taxonomy and leading severity frameworks including CVSS, CWE, and CAPEC.
- Secure Coding & Remediation: Demonstrated expertise across common vulnerability classes such as SQL injection, command injection, buffer overflows, deserialization flaws, Server-Side Request Forgery (SSRF), security misconfigurations, and privilege escalation.
- Verification Engineering: Experience in designing or evaluating two-part verification logic combining functional testing with vulnerability validation.
- Containerization Proficiency: Strong command of Docker and Docker Compose for setting up multi-container reproduction environments.
Ready to apply for CVE Vulnerability Expert?
Mercor states $70 – $90/hr for this role. The application is on their site and takes a few minutes.
Earns 25 points on this device — once per role per day
Dealuxe is not the employer, does not set the pay or the hiring terms, and cannot guarantee a role is still open. If you complete a purchase or form, we may earn a small commission at no extra cost to you.
Following an offer here banks 10 points on this device — once per page, within the 500 points a day anything on the site can earn.Ad Disclosure: the application link is a referral link.
While you job-hunt, save on the brands you already use
Browse 2,287 vetted brands with live commission offers and exclusive deals — every one open to everyone, no sign-in needed.
Explore all brand categories →Scroll through the piece and stay a moment. Reading pays 5 points and sharing pays 50. Following the apply link pays 25, and buying coins pays back 25 points a dollar.
Get stories in your inbox
New brand drops, deal breakdowns and the best of the Journal, straight from The Storefront Blog. Free forever — and subscribing pays you 25 points.
Drop your email in the box above, then bank the bonus. A paid plan pays 75 — three times the free tier — plus every paid-only post.
Copies the link with your caption. Grab a username to bank points across devices.
Boost this listing
See what's trendingTrade the points you've earned to push this up Trending and the homepage, where more readers will find it.
Similar roles
B2B Sales Expert (3+ YOE, US Only)
Mercor
The landscape of enterprise technology sales has undergone a fundamental transformation over the past few years. As artificial intelligence, advanced machine learning infrastructure, and complex enterprise software platforms dictate the…
- Location
- Remote — Worldwide
- Pay
- $50 – $70/hr
- Posted
P&C Actuary & Portfolio Risk Manager
Mercor
The Property and Casualty (P&C) insurance landscape has always been defined by complex calculations, rigorous statistical modeling, and deep domain expertise. From determining rate indications and managing catastrophic exposures to…
- Location
- Remote — Global
- Pay
- $80/hr
- Posted
Kubernetes Task Auditor
Mercor
The modern infrastructure landscape relies heavily on orchestration engines, containerization, and automated deployment pipelines. Among these tools, Kubernetes has cemented its status as the undisputed king of container orchestration.…
- Location
- Remote — Global
- Pay
- $70 – $90/hr
- Posted
ML Challenge Task Auditor
Mercor
The artificial intelligence landscape has matured far beyond simple prompt engineering and basic API integrations. Today, frontier AI research laboratories and hyper-growth technology enterprises are racing to build autonomous agents and…
- Location
- Remote — Global
- Pay
- $70 – $90/hr
- Posted
Accounting & Audit Domain Expert
Mercor
The accounting and financial services profession has traditionally revolved around meticulous ledgers, rigorous audit trails, regulatory compliance, and complex corporate reporting structures. Today, a revolutionary shift is occurring at…
- Location
- Remote — United States
- Pay
- $60 – $100/hr
- Posted
FP&A / Corporate Finance Evaluator
Mercor
The financial sector has traditionally been anchored by rigid corporate office hierarchies, grueling 60-hour workweeks in investment banking or corporate planning towers, and predictable career progression structures. However, a profound…
- Location
- Remote — Worldwide
- Pay
- $80 – $120/hr
- Posted
More finance & business listings
- Peluang Karier Global: Menjadi Business Analyst Bahasa Indonesia di Turing untuk Mengembangkan AI Masa Depan
- Gabay sa Pagpasok bilang Business Analyst (Tagalog Language) sa Turing
- Alt du trenger å vite om rollen som Business Analyst (Norwegian) hos Turing
- Business Analyst (French Language)
- Finance Expert
- Small Business Owners (AI Response Evaluation) - Japanese Business Document
- Shaping Business AI: The Definitive Guide to Turing’s Small Business English Document Project
- Senior Accounting & Finance Advisor
Be the first to comment
Loading comments…