Mercor · Finance & specialist
CVE Vulnerability Expert - review AI outputs in your specialty
Listed on Mercor as “CVE Vulnerability Expert”
What this actually is
You bring your specialist expertise to AI evaluation. The shape of the work varies but the pattern is the same: review outputs, rate quality, write prompts, flag errors. The platform title (CVE Vulnerability Expert) reflects the rate band and the expertise required, not the day-to-day work.
Advertisement
Can you do this on your visa?
F-2 / F-4 / F-5 / F-6: open. E-1 to E-7: needs concurrent-employment permit. D-2 / D-4 students: S-3 permit, 20 hr/week cap. D-10 / D-8: case by case.
Korean tax on USD income
First 5 years in Korea: foreign-source income only taxed if remitted into Korea. After year 5: worldwide income. Full tax guide.
Original posting from Mercor
Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks used to train and evaluate a frontier AI lab's models. You'll assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions - and provide clear, rubric-based written feedback.
Basic Qualifications
• 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
• Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC)
• Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation)
• Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests)
• Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Preferred Qualifications
• OSCP, GPEN, GWAPT, or equivalent offensive-security certification
• Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code
• Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling
• Prior technical content review, assessment design, or QA for security-focused engineering tasks
Quoted from Mercor’s public listing on 2026-09-08. We don’t edit platform copy; honest framing is in the title and the “what this actually is” block above.
Related AI training jobs
Mercor · Finance & specialist
Accounting Expert - review AI outputs in your specialty
$70-$80/hr · Remote · USD
Mercor · Finance & specialist
Advisory & Transaction Services Expert (M&A / Valuation) - review AI outputs in your specialty
$80-$120/hr · Remote · USD
Mercor · Finance & specialist
Agency Brand Design Expert - review AI outputs in your specialty
$80-$150/hr · Remote · USD
Mercor · Finance & specialist
AI Safety Experts — English & Assamese
$20-$22/hr · Remote · USD
More on this platform
About Mercor
AI-interview-based talent network. One application, voice interview with their AI, then matched to projects across coding, research, and specialist work. Pay scales with track and seniority.
Mercor review: AI-interview talent network
4.1/5 on Glassdoor, fastest-growing platform in the category (+509% YoY). What the AI video interview actually asks, real pay across coding/research/medical/legal/finance tracks ($25-$200/hr), and the project-availability problem.
See all AI training jobs
Browse by category and compare across all eight platforms we cover.