Logo for Anyone AI

Application Security Engineer – CVE & Vulnerability Research

Role overview

Qualifications

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE, CVSS, CWE, and common vulnerability classes
  • Experience identifying and remediating vulnerabilities such as SQL injection, Command injection, SSRF, Deserialization vulnerabilities, Buffer overflows, Privilege escalation, Access control issues, Security misconfigurations
  • Proficiency with Docker and Docker Compose

Responsibilities

  • Reviewing CVE reproduction environments for technical accuracy
  • Determining whether vulnerabilities faithfully reproduce the original attack vector and impact
  • Evaluating proposed security fixes and remediation strategies
  • Providing recommendations for improving vulnerability reproductions, fixes, and verification logic

Key facts

Hard skills

About the company

Anyone AI logo

Anyone AI

E-Learning / EdTech

We invest in talent from Latam to bridge the talent gap in AI. Join our AI community: www.anyoneai.com We are AI / ML experts and second-time entrepreneurs, members of the founding team at Deep Vision AI (acquired in early 2020). We've worked with many Fortune 500 companies completing multiple projects in the early days of AI while leveraging remote talent from LatAm. We are VC-backed from day 1 by top global investors like GFC -Global Founders Capital- (investors in Facebook, LinkedIn, Slack, Canva, Trivago, etc), Canvas Ventures (early investor in Coursera), Latitud Fund (the largest community of angel investors for LatAm including investments in QuintoAndar, La Haus, Clara, Platzi, OnTop, Pomelo, etc), among other investors.

Company details

IndustryE-Learning / EdTech
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Anyone AI is recruiting experienced Application Security Engineers and Vulnerability Researchers for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.

We’re looking for security professionals with hands-on experience in penetration testing, vulnerability research, or application security who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated.

What You’ll Work On

You’ll review technical security tasks involving:

  • CVE vulnerability reproduction

  • Exploit proof-of-concepts

  • Vulnerability remediation and secure coding

  • Application security testing

  • Docker-based vulnerability labs

  • Exploit verification scripts

  • Security regression testing

  • CVSS, CWE, and vulnerability classification

  • Environment and configuration analysis

  • Edge cases and alternative attack paths

A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality.

What We’re Looking For

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research

  • Strong understanding of CVE, CVSS, CWE, and common vulnerability classes

  • Experience identifying and remediating vulnerabilities such as:

    • SQL injection

    • Command injection

    • SSRF

    • Deserialization vulnerabilities

    • Buffer overflows

    • Privilege escalation

    • Access control issues

    • Security misconfigurations

  • Strong understanding of secure coding and vulnerability remediation

  • Experience reviewing or developing exploit proof-of-concepts

  • Experience validating whether security fixes address the root cause rather than only the immediate exploit

  • Proficiency with Docker and Docker Compose

  • Ability to provide clear, technically rigorous written feedback

What You’ll Be Responsible For

  • Reviewing CVE reproduction environments for technical accuracy

  • Determining whether vulnerabilities faithfully reproduce the original attack vector and impact

  • Evaluating proposed security fixes and remediation strategies

  • Reviewing test suites that verify both:

    • Normal application functionality remains intact

    • The original exploit no longer succeeds

  • Identifying incomplete fixes and alternative exploitation paths

  • Reviewing Docker environments for correct software versions, services, networking, and configuration

  • Detecting potential regressions or new vulnerabilities introduced by a fix

  • Providing recommendations for improving vulnerability reproductions, fixes, and verification logic

Nice to Have

  • OSCP, GPEN, GWAPT, or equivalent security certification

  • Experience with responsible vulnerability disclosure or CVE reporting

  • Experience maintaining exploit proof-of-concept code

  • Experience writing automated security tests using tools such as:

    • Python

    • requests

    • curl

    • pwntools

    • Custom exploit harnesses

  • DevSecOps experience

  • Familiarity with SAST, DAST, and CI/CD security tooling

  • Experience developing or reviewing cybersecurity assessments or technical security challenges

  • Experience with AI evaluation, RLHF, or technical data projects

Engagement

Work Type: Remote
Engagement: Part-time, project-based consulting
Focus: Application security, vulnerability research, CVE reproduction, and remediation

This role is ideal for security engineers who enjoy understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at Anyone AI

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.