CVE Vulnerability Expert
About this role
CVE Vulnerability Expert
Remote | Independent Contractor | United States | $145,600–$187,200 annualized ($70–$90/hour)
About the Role
Apply your vulnerability research and application security expertise to help improve the quality and reliability of advanced AI systems.
As a CVE Vulnerability Expert, you’ll evaluate vulnerability reproduction and remediation tasks used to train and assess frontier AI models. You’ll determine whether CVE reproductions accurately reflect real-world vulnerabilities, remediation approaches are technically sound, verification logic is rigorous, and Docker-based environments faithfully recreate exploitable conditions.
Your technical judgment and written feedback will help ensure security-focused AI training and evaluation tasks meet a high standard of accuracy and practical relevance.
What You’ll Do
Evaluate vulnerability-reproduction tasks for quality, fidelity, completeness, and technical accuracy.
Assess whether CVE reproductions faithfully recreate the underlying vulnerability and exploitable conditions.
Review remediation approaches to determine whether proposed fixes effectively address the root cause.
Evaluate verification logic, including separate functionality tests and vulnerability tests.
Review Docker and Docker Compose environments to determine whether they accurately reproduce multi-container vulnerability scenarios.
Identify technical gaps, inaccuracies, or inconsistencies and provide clear, rubric-based written feedback.
Assess security tasks across a range of common vulnerability classes.
Apply established evaluation criteria consistently while using your professional security expertise to identify issues that may not be immediately apparent.
What You Bring
3+ years of hands-on professional experience in application security, penetration testing, vulnerability research, or a closely related field.
Strong understanding of CVE vulnerability taxonomy and security severity frameworks, including:
CVSS
CWE
CAPEC
Demonstrated expertise in secure coding and vulnerability remediation across common classes, including:
SQL injection
Command injection
Buffer overflow
Deserialization vulnerabilities
Server-side request forgery (SSRF)
Security misconfigurations
Privilege escalation
Experience designing or evaluating two-part verification logic, including functionality and vulnerability testing.
Strong proficiency with Docker and Docker Compose, particularly for multi-container vulnerability reproduction environments.
Strong analytical skills and the ability to assess technical security work with precision.
Excellent written communication and the ability to provide clear, structured technical feedback.
Preferred Qualifications
The following experience is valuable but not required:
OSCP, GPEN, GWAPT, or an equivalent offensive-security certification.
Experience with CVE disclosure or responsible vulnerability reporting.
Experience creating, maintaining, or evaluating exploit proof-of-concept code.
Background in DevSecOps and security-focused CI/CD pipelines.
Experience with SAST, DAST, or related application security tooling.
Experience reviewing technical content, designing assessments, or performing QA for security-focused engineering tasks.
Compensation & Engagement
Rate: $70–$90/hour
Annualized Equivalent: $145,600–$187,200
Location: United States
Work Arrangement: Fully remote
Engagement Type: Independent contractor
Schedule: Flexible
Payment: Weekly via Stripe or Wise
Annualized compensation is based on 2,080 hours per year for comparison purposes only. Actual earnings depend on the number of hours and projects completed.
Why This Opportunity?
Apply your offensive security and vulnerability research expertise to advanced AI development.
Evaluate realistic security scenarios involving CVEs, exploitation, remediation, and verification.
Help improve how AI systems understand and reason about application security.
Work remotely with a flexible schedule.
Contribute technical expertise to high-impact AI training and evaluation projects.
Use your security experience beyond traditional penetration testing and vulnerability assessment workflows.
Contract & Payment Terms
You will be engaged as an independent contractor.
Work is fully remote and can be completed on your own schedule.
Projects may be extended, shortened, or concluded early depending on project needs and performance.
Your work will not require access to confidential or proprietary information belonging to any employer, client, or institution.
Payments are made weekly via Stripe or Wise based on services rendered.
H-1B and STEM OPT candidates cannot be supported at this time.
Equal Opportunity
All qualified applicants will be considered without regard to legally protected characteristics. Reasonable accommodations are available upon request.
- Fully remote contract role open to candidates in United States.
- Compensation: $145,600 - $187,200/year, paid in USD.
- Vetted and managed by Recruitment Room — no placement fees for candidates.
- Flexible hours; part-time and full-time engagements available.
More CVE vulnerability taxonomy roles
- Generalist ExpertUnited States · $50 - $70/hour
- Supply Chain ManagerMultiple countries · $114,400 - $208,000/year
- Purchasing AgentMultiple countries · $62,400 - $135,200/year
- Management Analyst – Strategy & Business ConsultingMultiple countries · $60 - $120/hour
- Education & Tutoring ExpertUnited States · $50 - $100/hour
- Quality AnalystMultiple countries · $20 - $50/hour