CVE Vulnerability Expert
Mercor • Remote
Education
Not stated
Type
Hourly
Pay Rate
$70–$90/hr
Listed
39d ago
Apply opens Mercor in a new tab.
Apply Now → ⚡ Boost your chances - Optimize your resume with Rezi.aiAbout this role
From the Mercor listing
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback.
Basic Qualifications • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC) • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation) • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests) • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications • OSCP, GPEN, GWAPT, or equivalent offensive-security certification • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code • Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling • Prior technical content review, assessment design, or QA for security-focused engineering tasks
Requirements
- Must be eligible to work in Remote
- Fluent proficiency in English (Written & Verbal)
- Reliable high-speed internet connection
- Bachelor's degree or equivalent professional experience
- Demonstrated expertise in Software Engineering
How long hiring takes
Across the AI training platforms we refer candidates to, the median gap between referral and hire is about 30 days. It varies by platform and role, so treat it as a rough guide for this one.
Talent Pool members
Apply through this link and we can put you forward to Mercor when your profile is a strong match. Not every applicant is submitted. If you're not in the pool yet, set up your profile first.
Set up your profile →Why this role
Few outlets pay Software Engineering specialists what the leading AI labs pay for direct judgment. At $70–$90/hr, this CVE Vulnerability Expert role prices in the expertise itself, separate from hours billed or clients managed.
Skills and categories
Explore other opportunities in related specializations:
Related jobs
Legal Expert — Data Privacy and Cybersecurity
mercor • Software Engineering
$120 /hr
Cybersecurity Practitioner: Paid Expert Interviews (SOC, Incident Response, Detection, AppSec)
mercor • Software Engineering
$175 /hr
Cybersecurity Practitioner: Paid Expert Interviews (SOC, Incident Response, Detection, AppSec)
mercor • Software Engineering
$175 /hr
Power Systems Engineer (Substation, Transmission, Interconnection)
mercor • Software Engineering
$70 /hr
Browse All Jobs from Mercor
Discover more opportunities on Mercor that match your skills and interests.
View All Mercor Jobs →Verified Reviews
Community Reviews
Share your experience with Mercor
Help other candidates make better decisions by leaving a review.
Sign in to leave a reviewLeave your review
Common questions
Does it cost money to apply to Mercor?
No, applying and joining Mercor is free. Mercor's revenue comes from a fee it charges the client on top of your hourly rate, not from applicants. Treat any request for payment to join as a red flag.
Is Mercor for freelancers or full-time contractors?
Mercor places you with one client for a defined engagement, like 'Python Tutor for 3 months', rather than having you grab small tasks from a shared queue. Most roles function as steady contract work, not one-off gigs.
What does task-based AI training work look like?
Practical, hands-on data work: recording short videos, categorizing images, rating text responses, or analyzing data. Tasks are designed to be short and distinct, typically 5 to 60 minutes each.
What does asynchronous AI training work mean in practice?
No set hours, no check-ins, no meetings. You log in when you want, pick up an available task, complete it, and submit; nobody is waiting on you in real time. That's different from remote employment, where you're expected online during business hours. The tradeoff: you're competing with others for available tasks, so an empty queue means there's simply nothing to do until more work is released.
What does Software Engineering work look like for a CVE Vulnerability Expert?
Tasks here are scoped to Software Engineering, not generic labeling. As a CVE Vulnerability Expert, expect to draw on real domain judgment (evaluating outputs, correcting errors, or providing expert reasoning specific to Software Engineering) rather than following a one-size-fits-all rubric. If you don't have hands-on Software Engineering background, this is likely not the right listing to start with.
What specific skills does this listing call for?
Expert is named directly in the listing. If you don't have hands-on experience with this, expect the screening process to test for it directly rather than accepting adjacent experience as a substitute.
How much does this specific role pay?
This listing is posted at $70–$90/hr, an hourly rate. The range reflects experience level and negotiated terms, not a placeholder, so where you land in it depends on your background and the assessment. Pay can change between when we last checked the listing and when you apply, so confirm the current number on the platform's own application page before committing time.
What happens when I click Apply on this listing?
You'll be taken to Mercor's external site to complete your application there. This listing links through a referral, but the process is identical to applying directly; the link just routes you correctly. Create an account on their site and follow their onboarding steps.
How soon will I start working after applying to Mercor?
Not immediately. Mercor is a talent marketplace, not a task queue, so applying puts you in a pool of candidates. You start working only once a specific client, like a major AI lab, selects your profile, and that matching process can take weeks.