We are sharing a specialised part-time consulting opportunity for experienced vulnerability researchers and application security professionals with strong expertise in CVE analysis, vulnerability reproduction, secure remediation, and security testing.
This role focuses on evaluating vulnerability-reproduction and remediation tasks for technical accuracy, realism, completeness, and verification quality. Selected experts will review CVE-based scenarios, proposed fixes, security test logic, and containerised lab environments while providing clear, rubric-based technical feedback.
Key Responsibilities
CVE & Vulnerability Review
-
Evaluate vulnerability-reproduction tasks based on documented CVEs
-
Assess whether scenarios faithfully represent the underlying vulnerability
-
Review technical assumptions, affected components, and expected behaviour
-
Identify incomplete, inaccurate, or unrealistic reproductions
-
Apply practical judgement grounded in hands-on vulnerability research or application security experience
Vulnerability Classification
-
Review security issues using established vulnerability taxonomies
-
Apply frameworks such as CVE, CVSS, CWE, and CAPEC
-
Assess vulnerability classification and severity rationale
-
Identify incorrect or misleading categorisation
-
Evaluate whether reported security impact is supported by the technical evidence
Application Security & Remediation
-
Review proposed fixes for common application and system vulnerabilities
-
Assess remediation approaches involving issues such as SQL injection, command injection, buffer overflow, insecure deserialisation, SSRF, misconfigurations, and privilege escalation
-
Determine whether fixes address the underlying security issue rather than only its symptoms
-
Identify regressions or functionality problems introduced by remediation
-
Evaluate secure coding approaches for technical soundness
Verification & Security Testing
-
Review verification logic used to confirm vulnerability remediation
-
Evaluate paired functionality tests and vulnerability-focused tests
-
Assess whether tests demonstrate both preserved application behaviour and removal of the security weakness
-
Identify incomplete coverage or misleading validation
-
Determine whether verification criteria are sufficiently rigorous and reproducible
Docker-Based Security Labs
-
Review vulnerability reproduction environments built with Docker and Docker Compose
-
Assess whether multi-container environments accurately reproduce required conditions
-
Evaluate configuration, dependencies, networking, and service interactions
-
Identify environmental issues that could affect reproducibility
-
Review whether lab environments support consistent security evaluation
Technical Reproduction & QA
-
Assess whether security scenarios can be reproduced reliably
-
Review setup instructions, dependencies, configurations, and expected outcomes
-
Identify missing assumptions or inconsistencies affecting repeatability
-
Evaluate whether task scope is appropriate and technically complete
-
Distinguish environment defects from genuine security findings
Secure Development Review
-
Evaluate application changes from a secure-coding perspective
-
Identify incomplete or fragile remediation strategies
-
Review whether security fixes maintain intended application functionality
-
Assess code and configuration changes for security implications
-
Apply practical application-security judgement across different vulnerability classes
Security Tooling & Engineering Workflows
-
Review workflows involving secure development and vulnerability assessment
-
Apply familiarity with SAST, DAST, CI/CD security controls, and DevSecOps practices where relevant
-
Assess whether security checks are appropriately integrated into development processes
-
Identify gaps in validation or security gating
-
Evaluate security engineering recommendations for practical effectiveness
Rubric-Based Technical Evaluation
-
Assess assigned security tasks against structured technical criteria
-
Provide clear written explanations supporting evaluation decisions
-
Reference specific reproduction, remediation, testing, or configuration evidence
-
Apply evaluation standards consistently across assignments
-
Distinguish valid alternative security approaches from technically flawed solutions
Ideal Profile
-
3+ years of hands-on experience in application security, penetration testing, or vulnerability research
-
Strong understanding of CVE vulnerability taxonomy and severity frameworks
-
Practical knowledge of CVSS, CWE, and CAPEC
-
Strong secure-coding and remediation experience across common vulnerability classes
-
Experience reviewing or designing security verification logic
-
Proficiency with Docker and Docker Compose
-
Strong ability to evaluate whether vulnerability reproductions and remediation approaches are technically sound
-
Experience with responsible vulnerability disclosure or CVE reporting is advantageous
-
Experience maintaining security proof-of-concept code is advantageous
-
Background in DevSecOps, CI/CD security gating, SAST, or DAST tooling is preferred
-
Certifications such as OSCP, GPEN, GWAPT, or equivalent are advantageous
-
Previous technical review, security assessment design, or QA experience is preferred
-
Strong written communication and ability to provide precise technical feedback
Engagement Details
-
Part-time independent contractor engagement
-
Fully remote within the United States
-
Flexible scheduling based on project requirements
-
Compensation: $60–$80/hour
-
Work focuses on CVE analysis, vulnerability reproduction, secure remediation, verification logic, and security task evaluation
-
Projects may be extended, shortened, or concluded based on project needs and performance
-
Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party
-
H1-B and STEM OPT support is unavailable for this engagement
About the Platform
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.
By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.