Remote job
Application Security Engineer – CVE & Vulnerability Research
Job details
About this role
Role overview This part-time, project-based consulting role focuses on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments. The work is remote and well suited to security professionals who enjoy analyzing how vulnerabilities actually work and identifying subtle gaps that traditional testing may miss.
Responsibilities - Review CVE reproduction environments for technical accuracy and faithful reproduction of the original attack vector and impact. - Evaluate proposed security fixes and remediation strategies to determine whether they address the root cause. - Review test suites that confirm normal application functionality remains intact and that the original exploit no longer succeeds. - Identify incomplete fixes and alternative exploitation paths, including potential regressions introduced by a patch. - Audit Docker-based environments for correct software versions, services, networking, and configuration. - Provide clear, technically rigorous written recommendations for improving vulnerability reproductions, fixes, and verification logic.
Requirements - 3+ years of hands-on experience in application security, penetration testing, or vulnerability research. - Strong understanding of CVE, CVSS, CWE, and common vulnerability classes such as SQL injection, command injection, SSRF, deserialization flaws, buffer overflows, privilege escalation, access control issues, and security misconfigurations. - Demonstrated experience with secure coding practices and vulnerability remediation. - Track record of reviewing or developing exploit proof-of-concepts. - Proficiency with Docker and Docker Compose for building and inspecting vulnerable environments. - Ability to produce clear, technically rigorous written feedback.
Nice to have - OSCP, GPEN, GWAPT, or equivalent security certifications. - Experience with responsible vulnerability disclosure or CVE reporting, or maintaining exploit proof-of-concept code. - Familiarity with automated security testing using Python, requests, curl, pwntools, or custom exploit harnesses. - DevSecOps experience and familiarity with SAST, DAST, and CI/CD security tooling. - Experience developing or reviewing cybersecurity assessments, technical security challenges, or AI evaluation and RLHF projects.
Benefits and work setup - Fully remote, part-time, project-based consulting engagement focused on application security and vulnerability research.