13 дней назад
Application Security Engineers and Vulnerability Researchers (Cybersecurity)
65$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineers and Vulnerability Researchers (Cybersecurity): Reviewing CVE reproductions, exploit proof-of-concepts, remediation approaches, and verification environments with an accent on vulnerability research, secure coding, and Docker-based security testing. Focus on validating attack conditions, determining whether fixes address root causes, identifying alternative exploitation paths, and ensuring security regressions are detected.
Location: Remote from Argentina, Brazil, Chile, Colombia, Ecuador, Mexico, Portugal, Spain, or Uruguay
Salary: $65 per hour
Company
is recruiting security professionals for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.
What you will do
- Review CVE reproduction environments and determine whether they accurately recreate original attack conditions, vectors, and impact.
- Evaluate exploit proof-of-concepts, remediation strategies, and security fixes for root-cause coverage.
- Review test suites verifying that legitimate functionality remains intact and the original exploit no longer succeeds.
- Analyze Docker environments, including software versions, services, networking, and configuration.
- Identify incomplete fixes, alternative attack paths, regressions, and vulnerabilities introduced by remediation.
- Provide technically rigorous recommendations and written feedback on reproductions, fixes, and verification logic.
Requirements
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
- Strong knowledge of CVE, CVSS, CWE, common vulnerability classes, secure coding, and vulnerability remediation.
- Experience with SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
- Experience reviewing or developing exploit proof-of-concepts and validating that fixes address root causes.
- Proficiency with Docker and Docker Compose.
- Ability to provide clear, technically rigorous written feedback.
Nice to have
- OSCP, GPEN, GWAPT, or an equivalent security certification.
- Experience with responsible vulnerability disclosure, CVE reporting, or maintaining exploit proof-of-concept code.
- Experience writing automated security tests with Python, requests, curl, pwntools, or custom exploit harnesses.
- DevSecOps experience and familiarity with SAST, DAST, and CI/CD security tooling.
- Experience with cybersecurity assessments, technical security challenges, AI evaluation, RLHF, or technical data projects.
Culture & Benefits
- Fully remote engagement available from the listed countries.
- Part-time, project-based consulting work.
- Focus on application security, vulnerability research, CVE reproduction, and remediation.
- Opportunity to analyze real-world exploits and subtle security gaps in controlled environments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
14 дней назад
Senior Product Security Engineer (Contract)
12 дней назад
AI Security Engineer (Offensive & Defensive)
14 дней назад
Senior Application Security Engineer (AI)
111 000 - 144 400$
13 дней назад
Application Security Engineer
7 дней назад
AI Security Engineer
80 000 - 105 000$
7 дней назад
Application Security Engineer (AI)
85 000 - 105 000$