Назад
Company hidden
13 дней назад

Application Security Engineers and Vulnerability Researchers (Cybersecurity)

65$
Формат работы
remote (только Europe)
Тип работы
project
Грейд
senior
Английский
b2
Страна
Argentina/Chile/Spain +6 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineers and Vulnerability Researchers (Cybersecurity): Reviewing CVE reproductions, exploit proof-of-concepts, remediation approaches, and verification environments with an accent on vulnerability research, secure coding, and Docker-based security testing. Focus on validating attack conditions, determining whether fixes address root causes, identifying alternative exploitation paths, and ensuring security regressions are detected.

Location: Remote from Argentina, Brazil, Chile, Colombia, Ecuador, Mexico, Portugal, Spain, or Uruguay

Salary: $65 per hour

Company

hirify.global is recruiting security professionals for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.

What you will do

  • Review CVE reproduction environments and determine whether they accurately recreate original attack conditions, vectors, and impact.
  • Evaluate exploit proof-of-concepts, remediation strategies, and security fixes for root-cause coverage.
  • Review test suites verifying that legitimate functionality remains intact and the original exploit no longer succeeds.
  • Analyze Docker environments, including software versions, services, networking, and configuration.
  • Identify incomplete fixes, alternative attack paths, regressions, and vulnerabilities introduced by remediation.
  • Provide technically rigorous recommendations and written feedback on reproductions, fixes, and verification logic.

Requirements

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
  • Strong knowledge of CVE, CVSS, CWE, common vulnerability classes, secure coding, and vulnerability remediation.
  • Experience with SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
  • Experience reviewing or developing exploit proof-of-concepts and validating that fixes address root causes.
  • Proficiency with Docker and Docker Compose.
  • Ability to provide clear, technically rigorous written feedback.

Nice to have

  • OSCP, GPEN, GWAPT, or an equivalent security certification.
  • Experience with responsible vulnerability disclosure, CVE reporting, or maintaining exploit proof-of-concept code.
  • Experience writing automated security tests with Python, requests, curl, pwntools, or custom exploit harnesses.
  • DevSecOps experience and familiarity with SAST, DAST, and CI/CD security tooling.
  • Experience with cybersecurity assessments, technical security challenges, AI evaluation, RLHF, or technical data projects.

Culture & Benefits

  • Fully remote engagement available from the listed countries.
  • Part-time, project-based consulting work.
  • Focus on application security, vulnerability research, CVE reproduction, and remediation.
  • Opportunity to analyze real-world exploits and subtle security gaps in controlled environments.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →