CVE Vulnerability Expert
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models.
- Pay
- Firm hourly pay: $70-$90 per hour
- Location
- Remote — United States
- Eligibility
- Remote; check the U.S. location wording
- Qualification difficulty
- Selective
How current is this information?
The public role and application path were checked. Details can still change; this is not an endorsement or guarantee.
- Platform
- Mercor
- Fit category
- Software engineering
- Listing/source checked
- Sep 1, 2026
- Inventory presence checked
- Sep 28, 2026
- Apply link checked
- Sep 1, 2026
Application
Continue to the current Mercor listing
Apply on MercorOpens the current Mercor page in a new tab. This may be a referral link, and Specialist AI Work may be paid if the platform credits it. That does not change the role's advertised pay or how roles are ordered here.
What this role involves
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback.
Basic Qualifications • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC) • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation) • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests) • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications
• OSCP, GPEN, GWAPT, or equivalent offensive-security certification • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code • Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling • Prior technical content review, assessment design, or QA for security-focused engineering tasks
Before you apply
Review the main fit signals and unresolved details before opening the platform.
Why it may fit
- Professionals whose experience matches the current CVE Vulnerability Expert requirements.
- Applicants comfortable completing Mercor's role-specific assessment.
Check before applying
Reasons to pause
- You cannot meet the listing's stated remote or location eligibility.
- You need guaranteed acceptance, hours, or project duration.
Still to verify
- Review the official Mercor listing before applying. Requirements, screening, pay, hours, and project availability can change.
- The reviewed listing had limited public detail; check the current platform page for the full requirements.
What to prepare
- Complete Mercor's role-specific application or assessment.
- Review the current Mercor listing before applying.
Role tools
Where these choices are saved
Save, Not for me, Compare, and application tracking remain in this browser.
Application tips
- Complete Mercor's role-specific application or assessment carefully.
- Review the current Mercor listing and its eligibility details before applying.