Search Remote Jobs

CVE Vulnerability Researcher

🔥 22 hours ago

🗽 New York – Remote

infoinfo

đź’µ $60 - $80 / hour

⏱ Part Time

🟡 Mid-level

đźź  Senior

đź‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of 24-MAG

24-MAG

2 - 10 employees

🤝 B2B

đź’Ľ Consulting

B2B • Consulting

24-MAG is a commercial strategy and execution firm that helps B2B organizations design and implement systems, workflows, and operating rhythms for sales, client management, and cross-functional projects. They focus on transforming scattered processes into aligned, measurable, and scalable commercial functions—covering pipeline structure, account management frameworks, and operational discipline for teams seeking efficient, intentional growth.

đź“‹ Description

• Evaluate vulnerability-reproduction tasks based on documented CVEs • Assess whether scenarios faithfully represent underlying vulnerabilities • Review technical assumptions, affected components, expected behaviour, and reproduction completeness • Review security issues using CVE, CVSS, CWE, and CAPEC taxonomies and assess severity rationale • Review proposed fixes for application and system vulnerabilities, including SQL injection, command injection, buffer overflow, insecure deserialisation, SSRF, misconfigurations, and privilege escalation • Determine whether remediations address underlying security issues and identify regressions or functionality problems • Review verification logic, paired functionality tests, and vulnerability-focused security tests • Assess Docker and Docker Compose vulnerability-reproduction environments, including configuration, dependencies, networking, and service interactions • Assess technical reproducibility, setup instructions, dependencies, configurations, expected outcomes, scope, and completeness • Review application changes from a secure-coding perspective • Evaluate workflows involving SAST, DAST, CI/CD security controls, and DevSecOps practices • Assess assigned security tasks against structured technical criteria and provide clear rubric-based written feedback • Distinguish valid alternative security approaches from technically flawed solutions

🎯 Requirements

• 3+ years of hands-on experience in application security, penetration testing, or vulnerability research • Strong understanding of CVE vulnerability taxonomy and severity frameworks • Practical knowledge of CVSS, CWE, and CAPEC • Strong secure-coding and remediation experience across common vulnerability classes • Experience reviewing or designing security verification logic • Proficiency with Docker and Docker Compose • Strong ability to evaluate whether vulnerability reproductions and remediation approaches are technically sound • Experience with responsible vulnerability disclosure or CVE reporting is advantageous • Experience maintaining security proof-of-concept code is advantageous • Background in DevSecOps, CI/CD security gating, SAST, or DAST tooling is preferred • Certifications such as OSCP, GPEN, GWAPT, or equivalent are advantageous • Previous technical review, security assessment design, or QA experience is preferred • Strong written communication and ability to provide precise technical feedback • Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party • H1-B and STEM OPT support is unavailable for this engagement

🏖️ Benefits

• Part-time independent contractor engagement • Fully remote within the United States • Flexible scheduling based on project requirements • Projects may be extended, shortened, or concluded based on project needs and performance • H1-B and STEM OPT support is unavailable for this engagement

Apply Now

Similar Jobs

đź•’ August 13

Zonda

501 - 1000

🏗️ Construction

📣 Marketing

đź’Ľ Consulting

Part-time field researcher helping Zonda collect new-home construction data for the real estate industry. Driving assigned neighborhoods, inspecting lot status, mapping findings, and tracking mileage.

🇺🇸 United States – Remote

đź’µ $15 / hour

⏱ Part Time

🟡 Mid-level

đźź  Senior

đź•’ August 11

Zonda

501 - 1000

🏗️ Construction

📣 Marketing

đź’Ľ Consulting

Part-time field researcher driving neighborhoods for Zonda, a housing-market data and consulting provider. Recording new-home construction statuses on maps and reporting findings to managers.

🇺🇸 United States – Remote

đź’µ $13 / hour

⏱ Part Time

🟡 Mid-level

đźź  Senior

đź•’ July 29

Zonda

501 - 1000

🏗️ Construction

📣 Marketing

đź’Ľ Consulting

Field Researcher driving through neighborhoods to track new home construction for Zonda. Flexible part-time work perfect for those needing non-screen based tasks.

🇺🇸 United States – Remote

đź’µ $15 / hour

⏱ Part Time

🟡 Mid-level

đźź  Senior

đź•’ July 22

Accufile Inc

51 - 200

⚖️ Legal

📦 Logistics

📣 Marketing

Research & Knowledge Services Researcher providing legal research for client’s Marketing & Business Development team. Remote role requires 15–20 hours per week with flexible work arrangements.

đź•’ June 29

Catalist

51 - 200

đź’Ľ Consulting

📣 Marketing

Absentee and Early Vote Researcher analyzing civic data for progressive organizations at Catalist. Responsible for data collection and monitoring election regulations within the Data team.

🇺🇸 United States – Remote

đź’µ $20 / hour

⏱ Part Time

🟡 Mid-level

đźź  Senior