Logo for 24-MAG

Remote | CVE Vulnerability Researcher — $60–$80/hour

Role overview

Qualifications

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks
  • Practical knowledge of CVSS, CWE, and CAPEC
  • Strong secure-coding and remediation experience across common vulnerability classes

Responsibilities

  • Evaluate vulnerability-reproduction tasks based on documented CVEs
  • Assess whether scenarios faithfully represent the underlying vulnerability
  • Review proposed fixes for common application and system vulnerabilities
  • Review verification logic used to confirm vulnerability remediation

Key facts

  • Remote from: New York (USA)
  • Freelance
  • Mid-level (2-5 years)
  • Researcher
  • English

Hard skills

Other skills

  • Communication

About the company

24-MAG logo

24-MAG

Business Consulting & Services

Company details

IndustryBusiness Consulting & Services
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We are sharing a specialised part-time consulting opportunity for experienced vulnerability researchers and application security professionals with strong expertise in CVE analysis, vulnerability reproduction, secure remediation, and security testing.

This role focuses on evaluating vulnerability-reproduction and remediation tasks for technical accuracy, realism, completeness, and verification quality. Selected experts will review CVE-based scenarios, proposed fixes, security test logic, and containerised lab environments while providing clear, rubric-based technical feedback.

Key Responsibilities

CVE & Vulnerability Review

  • Evaluate vulnerability-reproduction tasks based on documented CVEs
  • Assess whether scenarios faithfully represent the underlying vulnerability
  • Review technical assumptions, affected components, and expected behaviour
  • Identify incomplete, inaccurate, or unrealistic reproductions
  • Apply practical judgement grounded in hands-on vulnerability research or application security experience

Vulnerability Classification

  • Review security issues using established vulnerability taxonomies
  • Apply frameworks such as CVE, CVSS, CWE, and CAPEC
  • Assess vulnerability classification and severity rationale
  • Identify incorrect or misleading categorisation
  • Evaluate whether reported security impact is supported by the technical evidence

Application Security & Remediation

  • Review proposed fixes for common application and system vulnerabilities
  • Assess remediation approaches involving issues such as SQL injection, command injection, buffer overflow, insecure deserialisation, SSRF, misconfigurations, and privilege escalation
  • Determine whether fixes address the underlying security issue rather than only its symptoms
  • Identify regressions or functionality problems introduced by remediation
  • Evaluate secure coding approaches for technical soundness

Verification & Security Testing

  • Review verification logic used to confirm vulnerability remediation
  • Evaluate paired functionality tests and vulnerability-focused tests
  • Assess whether tests demonstrate both preserved application behaviour and removal of the security weakness
  • Identify incomplete coverage or misleading validation
  • Determine whether verification criteria are sufficiently rigorous and reproducible

Docker-Based Security Labs

  • Review vulnerability reproduction environments built with Docker and Docker Compose
  • Assess whether multi-container environments accurately reproduce required conditions
  • Evaluate configuration, dependencies, networking, and service interactions
  • Identify environmental issues that could affect reproducibility
  • Review whether lab environments support consistent security evaluation

Technical Reproduction & QA

  • Assess whether security scenarios can be reproduced reliably
  • Review setup instructions, dependencies, configurations, and expected outcomes
  • Identify missing assumptions or inconsistencies affecting repeatability
  • Evaluate whether task scope is appropriate and technically complete
  • Distinguish environment defects from genuine security findings

Secure Development Review

  • Evaluate application changes from a secure-coding perspective
  • Identify incomplete or fragile remediation strategies
  • Review whether security fixes maintain intended application functionality
  • Assess code and configuration changes for security implications
  • Apply practical application-security judgement across different vulnerability classes

Security Tooling & Engineering Workflows

  • Review workflows involving secure development and vulnerability assessment
  • Apply familiarity with SAST, DAST, CI/CD security controls, and DevSecOps practices where relevant
  • Assess whether security checks are appropriately integrated into development processes
  • Identify gaps in validation or security gating
  • Evaluate security engineering recommendations for practical effectiveness

Rubric-Based Technical Evaluation

  • Assess assigned security tasks against structured technical criteria
  • Provide clear written explanations supporting evaluation decisions
  • Reference specific reproduction, remediation, testing, or configuration evidence
  • Apply evaluation standards consistently across assignments
  • Distinguish valid alternative security approaches from technically flawed solutions

Ideal Profile

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks
  • Practical knowledge of CVSS, CWE, and CAPEC
  • Strong secure-coding and remediation experience across common vulnerability classes
  • Experience reviewing or designing security verification logic
  • Proficiency with Docker and Docker Compose
  • Strong ability to evaluate whether vulnerability reproductions and remediation approaches are technically sound
  • Experience with responsible vulnerability disclosure or CVE reporting is advantageous
  • Experience maintaining security proof-of-concept code is advantageous
  • Background in DevSecOps, CI/CD security gating, SAST, or DAST tooling is preferred
  • Certifications such as OSCP, GPEN, GWAPT, or equivalent are advantageous
  • Previous technical review, security assessment design, or QA experience is preferred
  • Strong written communication and ability to provide precise technical feedback

Engagement Details

  • Part-time independent contractor engagement
  • Fully remote within the United States
  • Flexible scheduling based on project requirements
  • Compensation: $60–$80/hour
  • Work focuses on CVE analysis, vulnerability reproduction, secure remediation, verification logic, and security task evaluation
  • Projects may be extended, shortened, or concluded based on project needs and performance
  • Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party
  • H1-B and STEM OPT support is unavailable for this engagement

About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Researcher Related jobs

Other jobs at 24-MAG

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.