Skip to content
aitrainer.work - AI Training Jobs Platform
Software Engineering mercor

Cybersecurity Research Expert – Offensive Security & Vulnerability Research

Mercor • Remote

Education

Not stated

Type

Hourly

Pay Rate

$200–$250/hr

Listed

59d ago

Apply opens Mercor in a new tab.

Apply Now →

About this role

From the Mercor listing

We're looking for highly accomplished Cybersecurity Research Experts to help evaluate cutting-edge AI systems in advanced security reasoning, vulnerability analysis, exploit development, and secure software engineering. This project is ideal for practitioners with a strong track record in offensive security research and publicly recognised technical contributions.

What You'll Do

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.

  • Review technical writeups for correctness, exploitability, and mitigation quality.

  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.

  • Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.

  • Contribute to benchmark development for advanced AI security capabilities.

Ideal Background

We are looking for candidates with multiple of the following credentials:

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.

  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software.

  • Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).

  • Research experience at a well-respected security laboratory or academic research group (e.g., KAIST Security Lab, SSLab, university security research groups, or equivalent industry research organisations).

  • Author of high-quality security research publications, conference papers, or widely cited technical writeups.

  • Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.

Preferred Qualifications

  • Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.

  • Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.

  • Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.

  • Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.

  • Strong programming skills in C/C++, Rust, Python, Go, or Java.

  • Excellent written communication and ability to explain complex security concepts clearly.

Nice to Have

  • Hall of Fame recognition from major bug bounty programs.

  • Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.

  • Maintainer or significant contributor to well-known open-source security tools.

  • Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.

Why Join?

  • Work on frontier AI models tackling real-world cybersecurity problems.

  • Collaborate with leading researchers on advanced security evaluation tasks.

  • Help shape the next generation of AI systems for cybersecurity.

Requirements

  • Must be eligible to work in Remote
  • Fluent proficiency in English (Written & Verbal)
  • Reliable high-speed internet connection
  • Bachelor's degree or equivalent professional experience
  • Demonstrated expertise in Software Engineering

How long hiring takes

Across the AI training platforms we refer candidates to, the median gap between referral and hire is about 30 days. It varies by platform and role, so treat it as a rough guide for this one.

Within 2 weeks
~25%
Within 6 weeks
~60%
Within 3 months
~80%

Talent Pool members

Apply through this link and we can put you forward to Mercor when your profile is a strong match. Not every applicant is submitted. If you're not in the pool yet, set up your profile first.

Set up your profile →

Why this role

- Work on frontier AI models tackling real-world cybersecurity problems. - Collaborate with leading researchers on advanced security evaluation tasks.

Skills and categories

Explore other opportunities in related specializations:

Related jobs

Mercor

Browse All Jobs from Mercor

Discover more opportunities on Mercor that match your skills and interests.

View All Mercor Jobs →

Verified Reviews

Loading reviews…

Community Reviews

Loading reviews…
💬

Share your experience with Mercor

Help other candidates make better decisions by leaving a review.

Sign in to leave a review

Common questions

Is Mercor for freelancers or full-time contractors?

Mercor places you with one client for a defined engagement, like 'Python Tutor for 3 months', rather than having you grab small tasks from a shared queue. Most roles function as steady contract work, not one-off gigs.

Does Mercor's application require an on-camera interview?

Yes, every applicant records a video interview with an AI interviewer that asks questions about your resume. Clients review that recording to judge communication skills before matching, so there's no way to apply without going on camera.

Why do these AI training roles pay so much?

Because general knowledge isn't what's being tested. The model already knows the basics; what it needs is expertise on edge cases, the rare, difficult, highly technical judgment calls only a senior professional in the field would make correctly.

What does the day-to-day workload look like for elite-expert AI training roles?

Slow and deep, not fast and repetitive. A single task can take 45-60 minutes of researching citations or verifying complex calculations. Quality is what's being measured here, not throughput.

What does Software Engineering work look like for a Cybersecurity Research Expert – Offensive Security & Vulnerability Research?

Tasks here are scoped to Software Engineering, not generic labeling. As a Cybersecurity Research Expert – Offensive Security & Vulnerability Research, expect to draw on real domain judgment (evaluating outputs, correcting errors, or providing expert reasoning specific to Software Engineering) rather than following a one-size-fits-all rubric. If you don't have hands-on Software Engineering background, this is likely not the right listing to start with.

What specific skills does this listing call for?

Expert is named directly in the listing. If you don't have hands-on experience with this, expect the screening process to test for it directly rather than accepting adjacent experience as a substitute.

How much does this specific role pay?

This listing is posted at $200–$250/hr, an hourly rate. The range reflects experience level and negotiated terms, not a placeholder, so where you land in it depends on your background and the assessment. Pay can change between when we last checked the listing and when you apply, so confirm the current number on the platform's own application page before committing time.

What happens when I click Apply on this listing?

You'll be taken to Mercor's external site to complete your application there. This listing links through a referral, but the process is identical to applying directly; the link just routes you correctly. Create an account on their site and follow their onboarding steps.

How soon will I start working after applying to Mercor?

Not immediately. Mercor is a talent marketplace, not a task queue, so applying puts you in a pool of candidates. You start working only once a specific client, like a major AI lab, selects your profile, and that matching process can take weeks.