Data annotation job
CVE Vulnerability Expert
Mercor · Posted 1 week ago
- AI evaluation
- Coding
- Mathematics
About this role
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions, and provide clear, rubric-based written feedback.
Basic Qualifications
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
- Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)
- Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)
- Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)
- Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications
- OSCP, GPEN, GWAPT, or equivalent offensive-security certification
- Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code
- Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling
- Prior technical content review, assessment design, or QA for security-focused engineering tasks
This listing is aggregated by DataAnnotationJobs.org. Applications are processed by Mercor, not by this site.
Mercor is an AI-native talent marketplace connecting vetted domain experts such as doctors, lawyers, and engineers directly with frontier AI labs for RLHF, evaluation, and specialized training data at massive scale. See all Mercor jobs.
Apply for this role
Your details first, then a short screening test. Both are read as part of your application and go to Mercor, and we will tell you when similar roles appear.