CVE Vulnerability Expert - Security

Mercor
San Francisco, CA
Remote
Job Description
Role Overview

We are seeking a CVE Vulnerability Expert to evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training. The ideal candidate will have 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.

What You Will Do

You will evaluate CVE reproductions for faithfulness, verify rigorous logic, and provide clear, rubric-based written feedback to improve model outputs. You will also collaborate with AI research teams to enhance training data quality and downstream performance.

Why It Might Be a Fit

This role requires strong understanding of CVE vulnerability taxonomy and severity frameworks, demonstrated expertise in secure coding and remediation, and proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Requirements

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)
  • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)
  • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)
  • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
]]>