CVE Vulnerability Expert needed for advanced AI systems evaluation; requires 3+ years in application security and expertise in CVE taxonomy.
Compensation
$146K–$187K
yearly · USD
Experience
3–15 yrs
Location
Remote
United States
Compensation
$146K–$187K
yearly · USD
Experience
3–15 yrs
Location
Remote
United States
The Brief
TITLE
CVE Vulnerability Expert
TYPE
Contract
POSTED
Aug 27, 2026
JOB ID
01a04253
TITLE
CVE Vulnerability Expert
TYPE
Contract
POSTED
Aug 27, 2026
JOB ID
01a04253
Remote | Independent Contractor | United States | $145,600–$187,200 annualized ($70–$90/hour)
Apply your vulnerability research and application security expertise to help improve the quality and reliability of advanced AI systems.
As a CVE Vulnerability Expert, you’ll evaluate vulnerability reproduction and remediation tasks used to train and assess frontier AI models. You’ll determine whether CVE reproductions accurately reflect real-world vulnerabilities, remediation approaches are technically sound, verification logic is rigorous, and Docker-based environments faithfully recreate exploitable conditions.
Your technical judgment and written feedback will help ensure security-focused AI training and evaluation tasks meet a high standard of accuracy and practical relevance.
Evaluate vulnerability-reproduction tasks for quality, fidelity, completeness, and technical accuracy.
Assess whether CVE reproductions faithfully recreate the underlying vulnerability and exploitable conditions.
Review remediation approaches to determine whether proposed fixes effectively address the root cause.
Evaluate verification logic, including separate functionality tests and vulnerability tests.
Review Docker and Docker Compose environments to determine whether they accurately reproduce multi-container vulnerability scenarios.
Identify technical gaps, inaccuracies, or inconsistencies and provide clear, rubric-based written feedback.
Assess security tasks across a range of common vulnerability classes.
Apply established evaluation criteria consistently while using your professional security expertise to identify issues that may not be immediately apparent.
3+ years of hands-on professional experience in application security, penetration testing, vulnerability research, or a closely related field.
Strong understanding of CVE vulnerability taxonomy and security severity frameworks, including:
CVSS
CWE
CAPEC
Demonstrated expertise in secure coding and vulnerability remediation across common classes, including:
SQL injection
Command injection
Buffer overflow
Deserialization vulnerabilities
Server-side request forgery (SSRF)
Security misconfigurations
Privilege escalation
Experience designing or evaluating two-part verification logic, including functionality and vulnerability testing.
Strong proficiency with Docker and Docker Compose, particularly for multi-container vulnerability reproduction environments.
Strong analytical skills and the ability to assess technical security work with precision.
Excellent written communication and the ability to provide clear, structured technical feedback.
The following experience is valuable but not required:
OSCP, GPEN, GWAPT, or an equivalent offensive-security certification.
Experience with CVE disclosure or responsible vulnerability reporting.
Experience creating, maintaining, or evaluating exploit proof-of-concept code.
Background in DevSecOps and security-focused CI/CD pipelines.
Experience with SAST, DAST, or related application security tooling.
Experience reviewing technical content, designing assessments, or performing QA for security-focused engineering tasks.
Rate: $70–$90/hour
Annualized Equivalent: $145,600–$187,200
Location: United States
Work Arrangement: Fully remote
Engagement Type: Independent contractor
Schedule: Flexible
Payment: Weekly via Stripe or Wise
Annualized compensation is based on 2,080 hours per year for comparison purposes only. Actual earnings depend on the number of hours and projects completed.
Apply your offensive security and vulnerability research expertise to advanced AI development.
Evaluate realistic security scenarios involving CVEs, exploitation, remediation, and verification.
Help improve how AI systems understand and reason about application security.
Work remotely with a flexible schedule.
Contribute technical expertise to high-impact AI training and evaluation projects.
Use your security experience beyond traditional penetration testing and vulnerability assessment workflows.
You will be engaged as an independent contractor.
Work is fully remote and can be completed on your own schedule.
Projects may be extended, shortened, or concluded early depending on project needs and performance.
Your work will not require access to confidential or proprietary information belonging to any employer, client, or institution.
Payments are made weekly via Stripe or Wise based on services rendered.
H-1B and STEM OPT candidates cannot be supported at this time.
All qualified applicants will be considered without regard to legally protected characteristics. Reasonable accommodations are available upon request.
About the company
Recruitment Room is a global workforce solutions company helping businesses build, manage, and scale distributed teams across international markets. We partner with startups, scale-ups, SMEs, and enterprise organizations to deliver end-to-end workforce solutions that support business growth, operational efficiency, and global expansion.
Our services extend beyond talent acquisition to include Employer of Record (EOR), Contractor of Record (COR), contractor management, global payroll, HRIS, workforce strategy, recruitment process outsourcing (RPO), executive search, and AI-powered talent intelligence. By combining human expertise with intelligent technology, we simplify the complexities of hiring, employing, and managing talent across borders.
For professionals, Recruitment Room provides access to career opportunities with innovative employers worldwide while supporting long-term career growth through our global talent ecosystem.