Skip to content
Labeling Jobs

CVE Vulnerability Expert

Pay
$70 – $90 / Hour
Open to
  • United States
Apply

We earn a commission if you sign up through the links on this page. It costs you nothing and does not affect which jobs we list. How this works.

Skills
  • application security
  • penetration testing
  • vulnerability research
  • secure coding
  • docker
  • cvss

What you'll do

A frontier AI lab trains and evaluates its models on security tasks built around real CVEs: reproduce the vulnerable condition, then fix it. You audit those tasks from the defender's side and judge whether they are sound.

The review covers four things:

  • Fidelity: does the Docker or Docker Compose lab genuinely recreate the vulnerable conditions of the CVE, including the right versions and configuration?
  • Remediation: is the reference fix correct and complete, or does it only block the one test input?
  • Verification logic: each task has two sets of tests, one proving the application still works and one proving the vulnerability is closed. Both need to be rigorous, and a fix that breaks functionality must fail.
  • Completeness: is the task clear, scoped and consistent with the CVE's actual class and severity?

Output is rubric-based written feedback. The emphasis is on reproduction accuracy and fix quality; the value for the lab is models that patch vulnerabilities properly.

Who fits

Basic qualifications:

  • 3+ years in application security, penetration testing or vulnerability research
  • A strong grasp of CVE taxonomy and severity frameworks (CVSS, CWE, CAPEC)
  • Secure coding and remediation across common classes: injection, memory safety, deserialization, SSRF, misconfiguration, privilege escalation
  • Experience designing or evaluating paired functionality and vulnerability tests
  • Docker and Docker Compose for multi-container lab environments

Preferred: OSCP, GPEN, GWAPT or equivalent; CVE disclosure or responsible reporting experience; DevSecOps, CI/CD security gating or SAST/DAST background; and prior review or QA of security engineering content.

What it pays

$70–90 per hour, weekly via Stripe or Wise. H-1B and STEM OPT candidates cannot be supported. Hours and duration are not published.

Security practitioners should also know about Mercor's Cybersecurity Practitioner: Paid Expert Interviews listing at $125–175 per hour, which is interview-based rather than ongoing task review and targets SOC, incident response and detection backgrounds as well as AppSec.

Worth knowing

Good:

  • Uses exactly the skills of a working AppSec engineer, including lab building
  • Certifications are preferred, not required
  • Asynchronous, remote

Less good:

  • US-only, with the visa exclusion
  • Rate is modest compared with security consulting day rates
  • Building or checking multi-container labs can be time-consuming, and the ad does not say how that time is scoped
  • Independent contractor; projects can be extended, shortened or ended early

About this listing

Posted by Mercor as a remote hourly contract for US residents, confirmed open on 24 September 2026. Qualifications and pay are the ad's own. See Mercor.

More roles at Mercor

See all 304

Similar roles at other platforms

Guides about Mercor

See all 52

Browse similar roles

Not the right fit?

See every open role, or get new ones on Telegram or Discord as they are added.