All AI training jobs

Mercor · Finance & specialist

CVE Vulnerability Expert - review AI outputs in your specialty

Listed on Mercor as “CVE Vulnerability Expert

$70-$90/hrRemoteContractPaid in USD
ShareWhatsAppTelegramEmail

What this actually is

You bring your specialist expertise to AI evaluation. The shape of the work varies but the pattern is the same: review outputs, rate quality, write prompts, flag errors. The platform title (CVE Vulnerability Expert) reflects the rate band and the expertise required, not the day-to-day work.

Advertisement

Can you do this on your visa?

F-2 / F-4 / F-5 / F-6: open. E-1 to E-7: needs concurrent-employment permit. D-2 / D-4 students: S-3 permit, 20 hr/week cap. D-10 / D-8: case by case.

Korean tax on USD income

First 5 years in Korea: foreign-source income only taxed if remitted into Korea. After year 5: worldwide income. Full tax guide.

Original posting from Mercor

Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions - and provide clear, rubric-based written feedback.

Basic Qualifications

• 3+ years of hands-on experience in application security, penetration testing, or vulnerability research

• Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)

• Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)

• Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)

• Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments

Preferred Qualifications

• OSCP, GPEN, GWAPT, or equivalent offensive-security certification

• Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code

• Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling

• Prior technical content review, assessment design, or QA for security-focused engineering tasks

Quoted from Mercor’s public listing on 2026-09-08. We don’t edit platform copy; honest framing is in the title and the “what this actually is” block above.

Apply on Mercor