Application Security Engineer – CVE, Vulnerability Research

atAnyone AIRemoteAR flagArgentinaPart-timeApplication EngineerMid-levelSenior$65/hour

Posted 1 day ago

This is a fully remote position, open to applicants in Argentina.

📋 Description

• Assess technical security tasks that include CVE vulnerability reproduction, the creation of exploit proof-of-concepts, vulnerability remediation, secure coding practices, application security testing, Docker-based vulnerability labs, verification of exploits, security regression testing, CVSS, CWE, vulnerability classification, and analysis of environments and configurations as well as alternative attack vectors.

• Verify that vulnerability environments effectively replicate the conditions of the original attacks.

• Assess if the proposed solutions effectively eliminate vulnerabilities without disrupting legitimate functionality.

• Examine CVE reproduction environments for technical precision.

• Analyze proposed security solutions and remediation approaches.

• Review test suites to ensure that standard application functionality is preserved and that the original exploit is no longer effective.

• Pinpoint incomplete fixes and potential alternative exploitation methods.

• Inspect Docker environments for appropriate software versions, services, networking configurations, and setups.

• Identify any regressions or new vulnerabilities that may arise from fixes.

• Offer suggestions for enhancing vulnerability reproductions, solutions, and verification processes.


⛳️ Requirements

• A minimum of 3 years of practical experience in application security, penetration testing, or vulnerability research.

• A solid understanding of CVE, CVSS, CWE, and prevalent vulnerability categories.

• Proven experience in identifying and addressing SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.

• Strong knowledge of secure coding practices and vulnerability remediation techniques.

• Experience in reviewing or developing exploit proof-of-concepts.

• Ability to validate whether security fixes tackle the underlying causes of vulnerabilities.

• Proficiency in using Docker and Docker Compose.

• Capability to provide clear, precise, and technically thorough written feedback.

• Possession of OSCP, GPEN, GWAPT, or equivalent security certifications is advantageous.

• Experience with responsible vulnerability disclosure or CVE reporting is an asset.

• Familiarity with maintaining exploit proof-of-concept code is a plus.

• Experience in developing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses is beneficial.

• DevSecOps experience is a bonus.

• Knowledge of SAST, DAST, and CI/CD security tools is advantageous.

• Experience in creating or reviewing cybersecurity assessments or technical security challenges is a plus.

• Background in AI evaluation, RLHF, or technical data projects is a plus.


🏝️ Benefits

• Opportunity for remote work.

• Part-time, project-based consulting arrangement.

• Hourly compensation set at $65.

People also viewed

Zact1 day ago

Application Support Engineer

IN flagIndia OnlyFull-timeApplication Engineer
ApplyView job
Intuitive1 day ago

Clinical Applications Engineer

US flagNew York OnlyFull-timeApplication Engineer$132k – $223.5k/year
ApplyView job
Intuitive1 day ago

Clinical Applications Engineer

US flagOhio OnlyFull-timeApplication Engineer$132k – $223.5k/year
ApplyView job
Applied Research Solutions2 days ago

Senior Cloud Application Integration Engineer

US flagOhio OnlyFull-timeApplication Engineer
ApplyView job
Quanata2 days ago

Senior Application Engineer

US flagUnited States OnlyFull-timeApplication Engineer$232k – $379k/year
ApplyView job
Nexperia2 days ago

Principal Field Application Engineer, Senior

DE flagGermany OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers