Remote job
Application Security Engineer – CVE & Vulnerability Research
Job details
About this role
Role overview Review real-world vulnerability reproductions and proposed fixes to determine whether they accurately capture an attack and whether remediation addresses its underlying cause. This project-based consulting role combines application security analysis, controlled exploit verification, and review of security tests and environments. The engagement is remote and part-time.
Responsibilities - Examine vulnerability reproductions and proof-of-concept exploits for technical accuracy and realistic impact. - Check whether environments recreate the relevant software versions, services, networking, and configuration. - Evaluate proposed fixes to confirm that they address the root cause while preserving legitimate functionality. - Review tests that verify both normal behavior and that the original exploit no longer works. - Look for incomplete remediation, alternate attack paths, regressions, or vulnerabilities introduced by a change. - Provide clear recommendations for improving reproductions, fixes, and verification logic.
Requirements - At least 3 years of hands-on experience in application security, penetration testing, or vulnerability research. - Strong understanding of CVEs, CVSS, CWEs, secure coding, and common vulnerability types, such as injection, SSRF, deserialization, access control flaws, and privilege escalation. - Experience reviewing or developing proof-of-concept exploits and assessing whether fixes address the root cause. - Proficiency with Docker and Docker Compose. - Ability to assess security tests and communicate findings in technically rigorous written feedback.
Nice to have Security certifications such as OSCP, GPEN, or GWAPT; responsible disclosure or CVE reporting; automated security testing with Python, curl, or custom harnesses; DevSecOps or SAST/DAST experience; or work on security assessments, AI evaluation, or technical data projects.