CVE Vulnerability Expert
Recruitment Room →CVE Vulnerability Expert at Recruitment Room is a contract role based in Remote · United States-231 (remote). The listing states pay of $145,600–$187,200 and asks for 3–15 yrs of experience. Listed skills: CVE vulnerability taxonomy. It was published on 27 August 2026 and was open at last check.
| Role | CVE Vulnerability Expert |
|---|---|
| Company | Recruitment Room |
| Location | Remote · United States-231 (remote) |
| Employment type | Contract |
| Pay (as listed) | $145,600–$187,200 |
| Experience asked | 3–15 yrs |
| Skills listed | CVE vulnerability taxonomy |
| Published | 27 August 2026 |
| Status | Open at last check |
CVE Vulnerability Expert
Remote | Independent Contractor | United States | $145,600–$187,200 annualized ($70–$90/hour)
About the Role
Apply your vulnerability research and application security expertise to help improve the quality and reliability of advanced AI systems.
As a CVE Vulnerability Expert, you’ll evaluate vulnerability reproduction and remediation tasks used to train and assess frontier AI models. You’ll determine whether CVE reproductions accurately reflect real-world vulnerabilities, remediation approaches are technically sound, verification logic is rigorous, and Docker-based environments faithfully recreate exploitable conditions.
Your technical judgment and written feedback will help ensure security-focused AI training and evaluation tasks meet a high standard of accuracy and practical relevance.
What You’ll Do
- Evaluate vulnerability-reproduction tasks for quality, fidelity, completeness, and technical accuracy.
- Assess whether CVE reproductions faithfully recreate the underlying vulnerability and exploitable conditions.
- Review remediation approaches to determine whether proposed fixes effectively address the root cause.
- Evaluate verification logic, including separate functionality tests and vulnerability tests.
- Review Docker and Docker Compose environments to determine whether they accurately reproduce multi-container vulnerability scenarios.
- Identify technical gaps, inaccuracies, or inconsistencies and provide clear, rubric-based written feedback.
- Assess security tasks across a range of common vulnerability classes.
- Apply established evaluation criteria consistently while using your professional security expertise to identify issues that may not be immediately apparent.
What You Bring
- 3+ years of hands-on professional experience in application security, penetration testing, vulnerability research, or a closely related field.
- Strong understanding of CVE vulnerability taxonomy and security severity frameworks, including: CVSS
- CWE
- CAPEC
- Demonstrated expertise in secure coding and vulnerability remediation across common classes, including: SQL injection
- Command injection
- Buffer overflow
- Deserialization vulnerabilities
- Server-side request forgery (SSRF)
- Security misconfigurations
- Privilege escalation
- Experience designing or evaluating two-part verification logic, including functionality and vulnerability testing.
- Strong proficiency with Docker and Docker Compose, particularly for multi-container vulnerability reproduction environments.
- Strong analytical skills and the ability to assess technical security work with precision.
- Excellent written communication and the ability to provide clear, structured technical feedback.
Preferred Qualifications
The following experience is valuable but not required:
- OSCP, GPEN, GWAPT, or an equivalent offensive-security certification.
- Experience with CVE disclosure or responsible vulnerability reporting.
- Experience creating, maintaining, or evaluating exploit proof-of-concept code.
- Background in DevSecOps and security-focused CI/CD pipelines.
- Experience with SAST, DAST, or related application security tooling.
- Experience reviewing technical content, designing assessments, or performing QA for security-focused engineering tasks.
Compensation & Engagement
- Rate: $70–$90/hour
- Annualized Equivalent: $145,600–$187,200
- Location: United States
- Work Arrangement: Fully remote
- Engagement Type: Independent contractor
- Schedule: Flexible
- Payment: Weekly via Stripe or Wise
Annualized compensation is based on 2,080 hours per year for comparison purposes only. Actual earnings depend on the number of hours and projects completed.
Why This Opportunity?
- Apply your offensive security and vulnerability research expertise to advanced AI development.
- Evaluate realistic security scenarios involving CVEs, exploitation, remediation, and verification.
- Help improve how AI systems understand and reason about application security.
- Work remotely with a flexible schedule.
- Contribute technical expertise to high-impact AI training and evaluation projects.
- Use your security experience beyond traditional penetration testing and vulnerability assessment workflows.
Contract & Payment Terms
- You will be engaged as an independent contractor.
- Work is fully remote and can be completed on your own schedule.
- Projects may be extended, shortened, or concluded early depending on project needs and performance.
- Your work will not require access to confidential or proprietary information belonging to any employer, client, or institution.
- Payments are made weekly via Stripe or Wise based on services rendered.
- H-1B and STEM OPT candidates cannot be supported at this time.
Equal Opportunity
All qualified applicants will be considered without regard to legally protected characteristics. Reasonable accommodations are available upon request.
Create a free OnJob profile to apply and see your AI match score before you apply. · Posted 27 Aug 2026.
CVE Vulnerability Expert at Recruitment Room — questions answered
What does the CVE Vulnerability Expert role at Recruitment Room pay?
The CVE Vulnerability Expert at Recruitment Room listing states pay of $145,600–$187,200 for the Remote · United States-231 (remote) position. That figure is taken directly from the employer's own posting as published, not estimated or averaged from other roles, and the same listing asks for 3–15 yrs of experience.
Is the CVE Vulnerability Expert role at Recruitment Room remote?
Yes — Recruitment Room advertises this CVE Vulnerability Expert role as remote, tied to Remote · United States-231, and it is listed as contract work. Remote terms come from the employer's own posting, so confirm the expected working hours, timezone and any on-site days with Recruitment Room before you apply.
What skills does the CVE Vulnerability Expert role at Recruitment Room require?
The CVE Vulnerability Expert at Recruitment Room listing names CVE vulnerability taxonomy. Those are the skills the employer put on the posting itself, so they are the ones worth matching in your profile and covering first in an interview.
How much experience do you need for the CVE Vulnerability Expert role at Recruitment Room?
Recruitment Room asks for 3–15 yrs of experience on this CVE Vulnerability Expert posting, alongside CVE vulnerability taxonomy. Employers commonly consider candidates slightly under a stated band when the listed skills line up.
Is the CVE Vulnerability Expert role at Recruitment Room still open?
The CVE Vulnerability Expert posting at Recruitment Room was open at OnJob's last check of the employer's careers page, having been published on 27 August 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.
How do you apply for the CVE Vulnerability Expert role at Recruitment Room?
Apply to the CVE Vulnerability Expert at Recruitment Room role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile. Creating a profile is free and needs no card.
Explore more on OnJob
Hiring for a role like this?
Post a job on OnJob and reach AI-matched candidates.