CVE Vulnerability Expert
CVE Vulnerability Expert is an open role at Mercor Experts, available remotely, with pay listed as $70–$90/hr.
Applications open on Mercor Experts’s own site. How we make money.
About this role
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions — and provide clear, rubric-based written feedback. Basic Qualifications • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC) • Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation) • Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests) • Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments Preferred Qualifications • OSCP, GPEN, GWAPT, or equivalent offensive-security certification • Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code • Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling • Prior technical content review, assessment design, or QA for security-focused engineering tasks
Pay
$70–$90/hr
About Mercor Experts
Mercor Experts's connection to Mercor: Direct expert network. Law, medicine, finance, engineering, operations and AI evaluation
Ownership confidence: Confirmed. See the full network profile →
Similar open roles
Frequently asked questions
How do I apply for the CVE Vulnerability Expert role at Mercor Experts?
Applications go through Mercor Experts's own portal - HumanSourcer links to the listing and never collects applications or handles hiring. Mercor Experts's access model is "Apply" (Profile / role application). This listing was first seen here on August 27, 2026 and was still live at the last check.
Is the CVE Vulnerability Expert role at Mercor Experts remote?
Yes - Mercor Experts lists this role as remote.
What does the CVE Vulnerability Expert role at Mercor Experts pay?
Mercor Experts lists this role's pay as $70–$90/hr, quoted from the listing rather than estimated.
What kind of work is CVE Vulnerability Expert?
Coding / software engineering. Law, medicine, finance, engineering, operations and AI evaluation
Is Mercor Experts a legitimate AI-training platform?
Direct expert network - and that relationship is rated "Confirmed" here because it can be checked against www.mercor.com rather than taken on Mercor Experts's word. Confidence describes how well the ownership is evidenced. It is not a rating of how the platform treats the people who work for it, which no public source covers reliably.
Get new AI-training roles by email
One weekly digest of newly listed roles across every tracked network - pay where it's disclosed, no spam, unsubscribe anytime.
Free. See how we make money.