Logo for Mercor

Cybersecurity Expert - Offensive Security

Role overview

Qualifications

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
  • Publicly recognised bug bounty researcher with findings accepted by major programs.
  • Research experience at a well-respected security laboratory or academic research group.

Responsibilities

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
  • Review technical writeups for correctness, exploitability, and mitigation quality.
  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
  • Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.

About the company

Mercor logo

Mercor

Job Boards & Talent Marketplaces

Company details

IndustryJob Boards & Talent Marketplaces

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type: Contract
Compensation: $200–$250/hour
Location: Remote

Role Responsibilities

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
  • Review technical writeups for correctness, exploitability, and mitigation quality.
  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
  • Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
  • Contribute to benchmark development for advanced AI security capabilities.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
  • Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
  • Research experience at a well-respected security laboratory or academic research group.
  • Author of high-quality security research publications, conference papers, or widely cited technical writeups.
  • Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.

Preferred

  • Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
  • Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
  • Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
  • Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
  • Strong programming skills in C/C++, Rust, Python, Go, or Java.
  • Excellent written communication and ability to explain complex security concepts clearly.

Nice to Have

  • Hall of Fame recognition from major bug bounty programs.
  • Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
  • Maintainer or significant contributor to well-known open-source security tools.
  • Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cybersecurity Consultant Related jobs

Other jobs at Mercor

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.