8 hours ago
Remote, Spain +8 moreMid Level
Responsibilities
- Review CVE reproduction environments for technical accuracy and faithful reproduction of attack vectors and impact.
- Evaluate vulnerability fixes, remediation strategies, and whether they address root causes rather than only immediate exploits.
- Review tests verifying that normal application functionality remains intact and the original exploit no longer succeeds.
- Identify incomplete fixes, alternative exploitation paths, regressions, and vulnerabilities introduced by remediation.
- Review Docker environments, including software versions, services, networking, and configuration.
- Provide technically rigorous recommendations and written feedback on vulnerability reproductions, fixes, and verification logic.
Requirements
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
- Strong understanding of CVE, CVSS, CWE, common vulnerability classes, secure coding, and vulnerability remediation.
- Experience with vulnerabilities including SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
- Experience reviewing or developing exploit proof-of-concepts and validating security fixes.
- Proficiency with Docker and Docker Compose.
- Ability to provide clear, technically rigorous written feedback.
- Preferred qualifications include OSCP, GPEN, GWAPT, or equivalent certification; responsible vulnerability disclosure or CVE reporting; exploit proof-of-concept maintenance; automated security testing with Python, requests, curl, pwntools, or custom exploit harnesses; DevSecOps; SAST, DAST, and CI/CD security tooling; cybersecurity assessments or technical security challenges; and AI evaluation, RLHF, or technical data project experience.
Benefits
- Remote work arrangement.
- Part-time, project-based consulting engagement.