About the job Remote | CVE Vulnerability Researcher — $60–$80/hour
We are sharing a specialised part-time consulting opportunity for experienced vulnerability researchers and application security professionals with strong expertise in CVE analysis, vulnerability reproduction, secure remediation, and security testing.
This role focuses on evaluating vulnerability-reproduction and remediation tasks for technical accuracy, realism, completeness, and verification quality. Selected experts will review CVE-based scenarios, proposed fixes, security test logic, and containerised lab environments while providing clear, rubric-based technical feedback.
Key Responsibilities
CVE & Vulnerability Review
- Evaluate vulnerability-reproduction tasks based on documented CVEs
- Assess whether scenarios faithfully represent the underlying vulnerability
- Review technical assumptions, affected components, and expected behaviour
- Identify incomplete, inaccurate, or unrealistic reproductions
- Apply practical judgement grounded in hands-on vulnerability research or application security experience
Vulnerability Classification
- Review security issues using established vulnerability taxonomies
- Apply frameworks such as CVE, CVSS, CWE, and CAPEC
- Assess vulnerability classification and severity rationale
- Identify incorrect or misleading categorisation
- Evaluate whether reported security impact is supported by the technical evidence
Application Security & Remediation
- Review proposed fixes for common application and system vulnerabilities
- Assess remediation approaches involving issues such as SQL injection, command injection, buffer overflow, insecure deserialisation, SSRF, misconfigurations, and privilege escalation
- Determine whether fixes address the underlying security issue rather than only its symptoms
- Identify regressions or functionality problems introduced by remediation
- Evaluate secure coding approaches for technical soundness
Verification & Security Testing
- Review verification logic used to confirm vulnerability remediation
- Evaluate paired functionality tests and vulnerability-focused tests
- Assess whether tests demonstrate both preserved application behaviour and removal of the security weakness
- Identify incomplete coverage or misleading validation
- Determine whether verification criteria are sufficiently rigorous and reproducible
Docker-Based Security Labs
- Review vulnerability reproduction environments built with Docker and Docker Compose
- Assess whether multi-container environments accurately reproduce required conditions
- Evaluate configuration, dependencies, networking, and service interactions
- Identify environmental issues that could affect reproducibility
- Review whether lab environments support consistent security evaluation
Technical Reproduction & QA
- Assess whether security scenarios can be reproduced reliably
- Review setup instructions, dependencies, configurations, and expected outcomes
- Identify missing assumptions or inconsistencies affecting repeatability
- Evaluate whether task scope is appropriate and technically complete
- Distinguish environment defects from genuine security findings
Secure Development Review
- Evaluate application changes from a secure-coding perspective
- Identify incomplete or fragile remediation strategies
- Review whether security fixes maintain intended application functionality
- Assess code and configuration changes for security implications
- Apply practical application-security judgement across different vulnerability classes
Security Tooling & Engineering Workflows
- Review workflows involving secure development and vulnerability assessment
- Apply familiarity with SAST, DAST, CI/CD security controls, and DevSecOps practices where relevant
- Assess whether security checks are appropriately integrated into development processes
- Identify gaps in validation or security gating
- Evaluate security engineering recommendations for practical effectiveness
Rubric-Based Technical Evaluation
- Assess assigned security tasks against structured technical criteria
- Provide clear written explanations supporting evaluation decisions
- Reference specific reproduction, remediation, testing, or configuration evidence
- Apply evaluation standards consistently across assignments
- Distinguish valid alternative security approaches from technically flawed solutions
Ideal Profile
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
- Strong understanding of CVE vulnerability taxonomy and severity frameworks
- Practical knowledge of CVSS, CWE, and CAPEC
- Strong secure-coding and remediation experience across common vulnerability classes
- Experience reviewing or designing security verification logic
- Proficiency with Docker and Docker Compose
- Strong ability to evaluate whether vulnerability reproductions and remediation approaches are technically sound
- Experience with responsible vulnerability disclosure or CVE reporting is advantageous
- Experience maintaining security proof-of-concept code is advantageous
- Background in DevSecOps, CI/CD security gating, SAST, or DAST tooling is preferred
- Certifications such as OSCP, GPEN, GWAPT, or equivalent are advantageous
- Previous technical review, security assessment design, or QA experience is preferred
- Strong written communication and ability to provide precise technical feedback
Engagement Details
- Part-time independent contractor engagement
- Fully remote within the United States
- Flexible scheduling based on project requirements
- Compensation: $60–$80/hour
- Work focuses on CVE analysis, vulnerability reproduction, secure remediation, verification logic, and security task evaluation
- Projects may be extended, shortened, or concluded based on project needs and performance
- Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party
- H1-B and STEM OPT support is unavailable for this engagement
About the Platform
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.
By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.