Anyone AI

Application Security Engineer – CVE & Vulnerability Research

Anyone AI
Apply
8 hours ago
Remote, Spain +8 moreMid Level

Responsibilities

  • Review CVE reproduction environments for technical accuracy and faithful reproduction of attack vectors and impact.
  • Evaluate vulnerability fixes, remediation strategies, and whether they address root causes rather than only immediate exploits.
  • Review tests verifying that normal application functionality remains intact and the original exploit no longer succeeds.
  • Identify incomplete fixes, alternative exploitation paths, regressions, and vulnerabilities introduced by remediation.
  • Review Docker environments, including software versions, services, networking, and configuration.
  • Provide technically rigorous recommendations and written feedback on vulnerability reproductions, fixes, and verification logic.

Requirements

  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
  • Strong understanding of CVE, CVSS, CWE, common vulnerability classes, secure coding, and vulnerability remediation.
  • Experience with vulnerabilities including SQL injection, command injection, SSRF, deserialization vulnerabilities, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
  • Experience reviewing or developing exploit proof-of-concepts and validating security fixes.
  • Proficiency with Docker and Docker Compose.
  • Ability to provide clear, technically rigorous written feedback.
  • Preferred qualifications include OSCP, GPEN, GWAPT, or equivalent certification; responsible vulnerability disclosure or CVE reporting; exploit proof-of-concept maintenance; automated security testing with Python, requests, curl, pwntools, or custom exploit harnesses; DevSecOps; SAST, DAST, and CI/CD security tooling; cybersecurity assessments or technical security challenges; and AI evaluation, RLHF, or technical data project experience.

Benefits

  • Remote work arrangement.
  • Part-time, project-based consulting engagement.

Tech Stack

Categories

Contact me