Logo for Mercor

CVE Vulnerability Expert - Security

Role overview

Qualifications

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC).
  • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation).
  • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Responsibilities

  • Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training.
  • Assess CVE reproductions for faithfulness and ensure fixes are sound.
  • Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions.
  • Provide clear, rubric-based written feedback to improve model outputs.

About the company

Mercor logo

Mercor

Job Boards & Talent Marketplaces

Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day.

Company details

IndustryJob Boards & Talent Marketplaces
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: CVE Vulnerability Expert
Type: Contract
Compensation: $70–$90/hour
Location: Remote

Role Responsibilities

  • Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training.
  • Assess CVE reproductions for faithfulness and ensure fixes are sound.
  • Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions.
  • Provide clear, rubric-based written feedback to improve model outputs.
  • Collaborate with AI research teams to enhance training data quality and downstream performance.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC).
  • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation).
  • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests).
  • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Preferred

  • OSCP, GPEN, GWAPT, or equivalent offensive-security certification.
  • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code.
  • Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling.
  • Prior technical content review, assessment design, or QA for security-focused engineering tasks.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Mercor

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.