Application Security Specialist - Fully Remote | Upto $90/hr

🏢 mercor · all mercor jobs
📍 United States
💰 USD 70 - 90 / hourly
📅 Posted 2026-08-30 · via Himalayas
🏷 Application-Security,Vulnerability-Research,Penetration-Testing,CVE,Security-Engineering,Application-Security-Specialist,Application-Security-Analyst,Application-Security-Engineer,Application-Security-Consultant,App-Security-Specialist,Application-Security-Tester
Apply on original site ↗

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey .

Position: CVE Vulnerability Expert
Type: Contract
Compensation: $70–$90/hour
Location: Remote
Role Responsibilities

- Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training.

- Assess CVE reproductions for faithfulness and ensure fixes are sound.

- Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions.

- Provide clear, rubric-based written feedback to improve model outputs.

- Collaborate with AI research teams to enhance training data quality and downstream performance.

- Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.

- Strong understanding of CVE vulnerability taxonomy and severity frameworks ( CVSS , CWE , CAPEC ).

- Demonstrated expertise in secure coding and remediation across common vulnerability classes ( SQL injection , command injection , buffer overflow , deserialization , SSRF , misconfigurations , privilege escalation ).

- Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests).

- Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Preferred

- OSCP , GPEN , GWAPT , or equivalent offensive-security certification.

- Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code.

- Background in DevSecOps , CI/CD security gating, or SAST/DAST tooling.

- Prior technical content review, assessment design, or QA for security-focused engineering tasks.

Application Process (Takes 20–30 mins to complete)

- Upload resume

- AI interview based on your resume

- Submit form

Resources & Support

- For details about the interview process and platform information, please check:

- For any help or support, reach out to:

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Originally posted on Himalayas

← All remote jobs

Similar for you