CVE Vulnerability Expert
- Pay
- $70 – $90 / Hour
- Open to
United States
- Apply
We earn a commission if you sign up through the links on this page. It costs you nothing and does not affect which jobs we list. How this works.
- Skills
- application security
- penetration testing
- vulnerability research
- secure coding
- docker
- cvss
What you'll do
A frontier AI lab trains and evaluates its models on security tasks built around real CVEs: reproduce the vulnerable condition, then fix it. You audit those tasks from the defender's side and judge whether they are sound.
The review covers four things:
- Fidelity: does the Docker or Docker Compose lab genuinely recreate the vulnerable conditions of the CVE, including the right versions and configuration?
- Remediation: is the reference fix correct and complete, or does it only block the one test input?
- Verification logic: each task has two sets of tests, one proving the application still works and one proving the vulnerability is closed. Both need to be rigorous, and a fix that breaks functionality must fail.
- Completeness: is the task clear, scoped and consistent with the CVE's actual class and severity?
Output is rubric-based written feedback. The emphasis is on reproduction accuracy and fix quality; the value for the lab is models that patch vulnerabilities properly.
Who fits
Basic qualifications:
- 3+ years in application security, penetration testing or vulnerability research
- A strong grasp of CVE taxonomy and severity frameworks (CVSS, CWE, CAPEC)
- Secure coding and remediation across common classes: injection, memory safety, deserialization, SSRF, misconfiguration, privilege escalation
- Experience designing or evaluating paired functionality and vulnerability tests
- Docker and Docker Compose for multi-container lab environments
Preferred: OSCP, GPEN, GWAPT or equivalent; CVE disclosure or responsible reporting experience; DevSecOps, CI/CD security gating or SAST/DAST background; and prior review or QA of security engineering content.
What it pays
$70–90 per hour, weekly via Stripe or Wise. H-1B and STEM OPT candidates cannot be supported. Hours and duration are not published.
Security practitioners should also know about Mercor's Cybersecurity Practitioner: Paid Expert Interviews listing at $125–175 per hour, which is interview-based rather than ongoing task review and targets SOC, incident response and detection backgrounds as well as AppSec.
Worth knowing
Good:
- Uses exactly the skills of a working AppSec engineer, including lab building
- Certifications are preferred, not required
- Asynchronous, remote
Less good:
- US-only, with the visa exclusion
- Rate is modest compared with security consulting day rates
- Building or checking multi-container labs can be time-consuming, and the ad does not say how that time is scoped
- Independent contractor; projects can be extended, shortened or ended early
About this listing
Posted by Mercor as a remote hourly contract for US residents, confirmed open on 24 September 2026. Qualifications and pay are the ad's own. See Mercor.
More roles at Mercor
See all 304Similar roles at other platforms
Guides about Mercor
See all 52- How much does Mercor pay? Rates from 304 live listingsPay breakdown
- The Mercor AI interview: what happens, what it checks, and what comes afterInterview prep
- Mercor vs Alignerr: which to apply to, and how they differPlatform comparison
- Mercor, micro1, Outlier, Alignerr and Handshake AI compared: which to apply to firstPlatform comparison
Browse similar roles
Not the right fit?
See every open role, or get new ones on Telegram or Discord as they are added.