Application Security Engineer – CVE & Vulnerability Research

Posted Yesterday
Be an Early Applicant
5 Locations
Remote
Mid level
Artificial Intelligence • Edtech • Machine Learning • Professional Services
The Role
Reviews CVE reproductions, exploit proof-of-concepts, vulnerability fixes, Docker-based labs, and security regression tests. Validates attack conditions, remediation effectiveness, root-cause resolution, application functionality, and alternative exploitation paths. Responsibilities include analyzing configurations, software versions, networking, test suites, and vulnerability classifications while providing rigorous technical feedback. The role is remote, part-time, and project-based, focused on application security and vulnerability research.
Summary Generated by Built In

Anyone AI is recruiting experienced Application Security Engineers and Vulnerability Researchers for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.

We’re looking for security professionals with hands-on experience in penetration testing, vulnerability research, or application security who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated.

What You’ll Work On

You’ll review technical security tasks involving:

  • CVE vulnerability reproduction

  • Exploit proof-of-concepts

  • Vulnerability remediation and secure coding

  • Application security testing

  • Docker-based vulnerability labs

  • Exploit verification scripts

  • Security regression testing

  • CVSS, CWE, and vulnerability classification

  • Environment and configuration analysis

  • Edge cases and alternative attack paths

A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality.

What We’re Looking For
  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research

  • Strong understanding of CVE, CVSS, CWE, and common vulnerability classes

  • Experience identifying and remediating vulnerabilities such as:

    • SQL injection

    • Command injection

    • SSRF

    • Deserialization vulnerabilities

    • Buffer overflows

    • Privilege escalation

    • Access control issues

    • Security misconfigurations

  • Strong understanding of secure coding and vulnerability remediation

  • Experience reviewing or developing exploit proof-of-concepts

  • Experience validating whether security fixes address the root cause rather than only the immediate exploit

  • Proficiency with Docker and Docker Compose

  • Ability to provide clear, technically rigorous written feedback

What You’ll Be Responsible For
  • Reviewing CVE reproduction environments for technical accuracy

  • Determining whether vulnerabilities faithfully reproduce the original attack vector and impact

  • Evaluating proposed security fixes and remediation strategies

  • Reviewing test suites that verify both:

    • Normal application functionality remains intact

    • The original exploit no longer succeeds

  • Identifying incomplete fixes and alternative exploitation paths

  • Reviewing Docker environments for correct software versions, services, networking, and configuration

  • Detecting potential regressions or new vulnerabilities introduced by a fix

  • Providing recommendations for improving vulnerability reproductions, fixes, and verification logic

Nice to Have
  • OSCP, GPEN, GWAPT, or equivalent security certification

  • Experience with responsible vulnerability disclosure or CVE reporting

  • Experience maintaining exploit proof-of-concept code

  • Experience writing automated security tests using tools such as:

    • Python

    • requests

    • curl

    • pwntools

    • Custom exploit harnesses

  • DevSecOps experience

  • Familiarity with SAST, DAST, and CI/CD security tooling

  • Experience developing or reviewing cybersecurity assessments or technical security challenges

  • Experience with AI evaluation, RLHF, or technical data projects

Engagement

Work Type: Remote
Engagement: Part-time, project-based consulting
Focus: Application security, vulnerability research, CVE reproduction, and remediation

This role is ideal for security engineers who enjoy understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.

Skills Required

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE, CVSS, CWE, and common vulnerability classes
  • Experience identifying and remediating SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations
  • Strong understanding of secure coding and vulnerability remediation
  • Experience reviewing or developing exploit proof-of-concepts
  • Experience validating whether security fixes address root causes rather than only immediate exploits
  • Proficiency with Docker and Docker Compose
  • Ability to provide clear, technically rigorous written feedback
  • OSCP, GPEN, GWAPT, or equivalent security certification
  • Experience with responsible vulnerability disclosure or CVE reporting
  • Experience maintaining exploit proof-of-concept code
  • Experience writing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses
  • DevSecOps experience
  • Familiarity with SAST, DAST, and CI/CD security tooling
  • Experience developing or reviewing cybersecurity assessments or technical security challenges
  • Experience with AI evaluation, RLHF, or technical data projects
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Year Founded: 2022

What We Do

Anyone AI is an edtech startup dedicated to bridging the AI talent gap by investing in software developers from Latin America. The company provides intensive, hands-on training programs in Machine Learning and Artificial Intelligence, led by industry experts. By combining technical skill development with employability support, Anyone AI prepares professionals for global career opportunities, helping them transition into high-impact roles within the rapidly evolving AI and technology sectors.

Similar Jobs

InterSystems Logo InterSystems

Administrative Assistant

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Database • Analytics
Easy Apply
Remote
Chile
2100 Employees

Cloudflare Logo Cloudflare

Senior Customer Engineer, LATAM - MCR (Santiago, Chile).

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Chile
4400 Employees

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sr. Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly

Domino Data Lab Logo Domino Data Lab

Support Engineer

Artificial Intelligence • Machine Learning
Remote or Hybrid
10 Locations
200 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account