Application Security Engineer – CVE, Vulnerability Research

atAnyone AIRemoteAR flagArgentinaFreelanceApplication EngineerMid-levelSenior$65/hour

Posted 3 days ago

This is a fully remote position, open to applicants in Argentina.

📋 Description

• Conduct reviews of technical security tasks that involve CVE vulnerability reproduction, development of exploit proof-of-concepts, vulnerability remediation, secure coding practices, application security testing, Docker-based vulnerability labs, verification of exploits, security regression testing, classification using CVSS/CWE, analysis of environments and configurations, and exploration of alternative attack paths.

• Evaluate whether vulnerability environments accurately simulate original attack scenarios.

• Assess if proposed solutions effectively eliminate vulnerabilities while maintaining legitimate functionality.

• Review CVE reproduction environments to ensure technical correctness.

• Verify that vulnerabilities accurately replicate the original attack vector and its impact.

• Analyze proposed security fixes and remediation approaches.

• Inspect test suites to confirm that normal application operations remain unaffected and that the initial exploit is no longer effective.

• Identify any incomplete fixes and alternative exploitation methods.

• Review Docker environments for appropriate software versions, services, networking, and configurations.

• Detect any regressions or new vulnerabilities introduced by fixes.

• Suggest enhancements for vulnerability reproductions, fixes, and verification processes.


⛳️ Requirements

• A minimum of 3 years of practical experience in application security, penetration testing, or vulnerability research.

• In-depth knowledge of CVE, CVSS, CWE, and prevalent vulnerability categories.

• Proven experience in identifying and addressing SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.

• Strong grasp of secure coding practices and vulnerability remediation techniques.

• Experience in reviewing or creating exploit proof-of-concepts.

• Capability to validate whether security fixes tackle the root cause of vulnerabilities.

• Proficiency in using Docker and Docker Compose.

• Strong ability to provide clear and technically sound written feedback.

• Possession of OSCP, GPEN, GWAPT, or equivalent security certifications.

• Experience in responsible vulnerability disclosure or CVE reporting processes.

• Skill in maintaining exploit proof-of-concept code.

• Experience in writing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses.

• Background in DevSecOps methodologies.

• Familiarity with SAST, DAST, and CI/CD security tools.

• Experience in developing or reviewing cybersecurity assessments or technical security challenges.

• Knowledge in AI evaluation, RLHF, or technical data projects.


🏝️ Benefits

• $65 per hour.

• Flexible remote work opportunity.

• Part-time, project-based consulting engagement.

People also viewed

Devexperts1 day ago

Application Support Engineer, Level 1

BR flagBrazil OnlyFull-timeApplication Engineer
ApplyView job
Copeland1 day ago

Applications Engineer

CO flagColombia OnlyFull-timeApplication Engineer
ApplyView job
Motive1 day ago

Site Reliability Engineer – Application Development, Kubernetes, Linux

US flagTexas OnlyFull-timeApplication Engineer$80k – $90k/year
ApplyView job
Intel Corporation1 day ago

Sales Application Engineer

CA flagCanada OnlyFull-timeApplication EngineerC$251.6k – C$355.2k/year
ApplyView job
Zact1 day ago

Senior Application Support Engineer – India

IN flagIndia OnlyFull-timeApplication Engineer
ApplyView job
Zact1 day ago

Senior Application Support Engineer

US flagUnited States OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers