
Application Security Engineer – CVE, Vulnerability Research
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Argentina.
• Assess technical security tasks that include CVE vulnerability reproduction, the creation of exploit proof-of-concepts, vulnerability remediation, secure coding practices, application security testing, Docker-based vulnerability labs, verification of exploits, security regression testing, CVSS, CWE, vulnerability classification, and analysis of environments and configurations as well as alternative attack vectors.
• Verify that vulnerability environments effectively replicate the conditions of the original attacks.
• Assess if the proposed solutions effectively eliminate vulnerabilities without disrupting legitimate functionality.
• Examine CVE reproduction environments for technical precision.
• Analyze proposed security solutions and remediation approaches.
• Review test suites to ensure that standard application functionality is preserved and that the original exploit is no longer effective.
• Pinpoint incomplete fixes and potential alternative exploitation methods.
• Inspect Docker environments for appropriate software versions, services, networking configurations, and setups.
• Identify any regressions or new vulnerabilities that may arise from fixes.
• Offer suggestions for enhancing vulnerability reproductions, solutions, and verification processes.
• A minimum of 3 years of practical experience in application security, penetration testing, or vulnerability research.
• A solid understanding of CVE, CVSS, CWE, and prevalent vulnerability categories.
• Proven experience in identifying and addressing SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
• Strong knowledge of secure coding practices and vulnerability remediation techniques.
• Experience in reviewing or developing exploit proof-of-concepts.
• Ability to validate whether security fixes tackle the underlying causes of vulnerabilities.
• Proficiency in using Docker and Docker Compose.
• Capability to provide clear, precise, and technically thorough written feedback.
• Possession of OSCP, GPEN, GWAPT, or equivalent security certifications is advantageous.
• Experience with responsible vulnerability disclosure or CVE reporting is an asset.
• Familiarity with maintaining exploit proof-of-concept code is a plus.
• Experience in developing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses is beneficial.
• DevSecOps experience is a bonus.
• Knowledge of SAST, DAST, and CI/CD security tools is advantageous.
• Experience in creating or reviewing cybersecurity assessments or technical security challenges is a plus.
• Background in AI evaluation, RLHF, or technical data projects is a plus.
• Opportunity for remote work.
• Part-time, project-based consulting arrangement.
• Hourly compensation set at $65.
Intuitive
Intuitive
Applied Research Solutions
Get handpicked remote jobs straight to your inbox weekly.