
CVE Vulnerability Researcher
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in New York.
• Analyze vulnerability-reproduction tasks according to documented CVEs.
• Evaluate whether scenarios accurately depict the underlying vulnerabilities.
• Examine technical assumptions, affected components, expected behaviors, and the completeness of reproductions.
• Review security concerns utilizing CVE, CVSS, CWE, and CAPEC taxonomies and assess the rationale for severity.
• Inspect proposed solutions for application and system vulnerabilities, including SQL injection, command injection, buffer overflow, insecure deserialization, SSRF, misconfigurations, and privilege escalation.
• Ascertain if remediations effectively address the underlying security issues and identify any regressions or functionality issues.
• Assess verification logic, corresponding functionality tests, and security tests focused on vulnerabilities.
• Evaluate Docker and Docker Compose vulnerability-reproduction environments, including configurations, dependencies, networking, and interactions between services.
• Analyze technical reproducibility, setup instructions, dependencies, configurations, expected outcomes, scope, and completeness.
• Review application modifications from a secure coding perspective.
• Evaluate workflows associated with SAST, DAST, CI/CD security controls, and DevSecOps methodologies.
• Assess assigned security tasks against structured technical criteria and provide clear, rubric-based written feedback.
• Differentiate between valid alternative security strategies and technically flawed solutions.
• Over 3 years of practical experience in application security, penetration testing, or vulnerability research.
• Robust understanding of the CVE vulnerability taxonomy and severity frameworks.
• Hands-on knowledge of CVSS, CWE, and CAPEC.
• Strong experience in secure coding and remediation across common vulnerability types.
• Background in reviewing or designing security verification logic.
• Proficient with Docker and Docker Compose.
• Excellent ability to assess whether vulnerability reproductions and remediation strategies are technically sound.
• Experience with responsible vulnerability disclosure or CVE reporting is a plus.
• Familiarity with maintaining security proof-of-concept code is advantageous.
• A background in DevSecOps, CI/CD security gating, SAST, or DAST tools is preferred.
• Certifications such as OSCP, GPEN, GWAPT, or equivalent are beneficial.
• Prior experience in technical review, security assessment design, or QA is preferred.
• Strong written communication skills and the ability to provide precise technical feedback.
• Work must be conducted without utilizing confidential or proprietary information belonging to any employer, client, institution, or other third party.
• H1-B and STEM OPT support is not available for this position.
• Part-time independent contractor engagement.
• Fully remote within the United States.
• Flexible scheduling based on project requirements.
• Projects may be extended, shortened, or concluded based on project needs and performance.
• H1-B and STEM OPT support is not available for this engagement.
Mercor
Conduent
Wormhole Labs
Ledcor
Get handpicked remote jobs straight to your inbox weekly.