YOUR NEXT CHAPTER
Application Security Engineer – CVE, Vulnerability Research
About the role
• Review technical security tasks involving CVE vulnerability reproduction, exploit proof-of-concepts, vulnerability remediation, secure coding, application security testing, Docker-based vulnerability labs, exploit verification scripts, security regression testing, CVSS/CWE classification, environment and configuration analysis, and alternative attack paths
• Determine whether vulnerability environments accurately recreate original attack conditions
• Assess whether proposed fixes eliminate vulnerabilities without breaking legitimate functionality
• Review CVE reproduction environments for technical accuracy
• Determine whether vulnerabilities faithfully reproduce the original attack vector and impact
• Evaluate proposed security fixes and remediation strategies
• Review test suites to verify normal application functionality remains intact and the original exploit no longer succeeds
• Identify incomplete fixes and alternative exploitation paths
• Review Docker environments for correct software versions, services, networking, and configuration
• Detect regressions or new vulnerabilities introduced by fixes
• Recommend improvements to vulnerability reproductions, fixes, and verification logic
• 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
• Strong understanding of CVE, CVSS, CWE, and common vulnerability classes
• Experience identifying and remediating SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations
• Strong understanding of secure coding and vulnerability remediation
• Experience reviewing or developing exploit proof-of-concepts
• Experience validating whether security fixes address the root cause
• Proficiency with Docker and Docker Compose
• Ability to provide clear, technically rigorous written feedback
• OSCP, GPEN, GWAPT, or equivalent security certification
• Experience with responsible vulnerability disclosure or CVE reporting
• Experience maintaining exploit proof-of-concept code
• Experience writing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses
• DevSecOps experience
• Familiarity with SAST, DAST, and CI/CD security tooling
• Experience developing or reviewing cybersecurity assessments or technical security challenges
• Experience with AI evaluation, RLHF, or technical data projects
• $65 per hour
• Remote work
• Part-time, project-based consulting engagement