
Application Security Engineer – CVE, Vulnerability Research
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Argentina.
• Conduct reviews of technical security tasks that involve CVE vulnerability reproduction, development of exploit proof-of-concepts, vulnerability remediation, secure coding practices, application security testing, Docker-based vulnerability labs, verification of exploits, security regression testing, classification using CVSS/CWE, analysis of environments and configurations, and exploration of alternative attack paths.
• Evaluate whether vulnerability environments accurately simulate original attack scenarios.
• Assess if proposed solutions effectively eliminate vulnerabilities while maintaining legitimate functionality.
• Review CVE reproduction environments to ensure technical correctness.
• Verify that vulnerabilities accurately replicate the original attack vector and its impact.
• Analyze proposed security fixes and remediation approaches.
• Inspect test suites to confirm that normal application operations remain unaffected and that the initial exploit is no longer effective.
• Identify any incomplete fixes and alternative exploitation methods.
• Review Docker environments for appropriate software versions, services, networking, and configurations.
• Detect any regressions or new vulnerabilities introduced by fixes.
• Suggest enhancements for vulnerability reproductions, fixes, and verification processes.
• A minimum of 3 years of practical experience in application security, penetration testing, or vulnerability research.
• In-depth knowledge of CVE, CVSS, CWE, and prevalent vulnerability categories.
• Proven experience in identifying and addressing SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
• Strong grasp of secure coding practices and vulnerability remediation techniques.
• Experience in reviewing or creating exploit proof-of-concepts.
• Capability to validate whether security fixes tackle the root cause of vulnerabilities.
• Proficiency in using Docker and Docker Compose.
• Strong ability to provide clear and technically sound written feedback.
• Possession of OSCP, GPEN, GWAPT, or equivalent security certifications.
• Experience in responsible vulnerability disclosure or CVE reporting processes.
• Skill in maintaining exploit proof-of-concept code.
• Experience in writing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses.
• Background in DevSecOps methodologies.
• Familiarity with SAST, DAST, and CI/CD security tools.
• Experience in developing or reviewing cybersecurity assessments or technical security challenges.
• Knowledge in AI evaluation, RLHF, or technical data projects.
• $65 per hour.
• Flexible remote work opportunity.
• Part-time, project-based consulting engagement.
Devexperts
Motive
Intel Corporation
Get handpicked remote jobs straight to your inbox weekly.