More jobs:
Application Security Engineer – CVE & Vulnerability Research
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-09-26
Listing for:
Hidden Jobs
Part Time
position Listed on 2026-09-26
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Role overview
This part-time, project-based consulting role focuses on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments. The work is remote and well suited to security professionals who enjoy analyzing how vulnerabilities actually work and identifying subtle gaps that traditional testing may miss.
Responsibilities- Review CVE reproduction environments for technical accuracy and faithful reproduction of the original attack vector and impact.
- Evaluate proposed security fixes and remediation strategies to determine whether they address the root cause.
- Review test suites that confirm normal application functionality remains intact and that the original exploit no longer succeeds.
- Identify incomplete fixes and alternative exploitation paths, including potential regressions introduced by a patch.
- Audit Docker-based environments for correct software versions, services, networking, and configuration.
- Provide clear, technically rigorous written recommendations for improving vulnerability reproductions, fixes, and verification logic.
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
- Strong understanding of CVE, CVSS, CWE, and common vulnerability classes such as SQL injection, command injection, SSRF, deserialization flaws, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
- Demonstrated experience with secure coding practices and vulnerability remediation.
- Track record of reviewing or developing exploit proof-of-concepts.
- Proficiency with Docker and Docker Compose for building and inspecting vulnerable environments.
- Ability to produce clear, technically rigorous written feedback.
- OSCP, GPEN, GWAPT, or equivalent security certifications.
- Experience with responsible vulnerability disclosure or CVE reporting, or maintaining exploit proof-of-concept code.
- Familiarity with automated security testing using Python, requests, curl, pwntools, or custom exploit harnesses.
- Dev Sec Ops experience and familiarity with SAST, DAST, and CI/CD security tooling.
- Experience developing or reviewing cybersecurity assessments, technical security challenges, or AI evaluation and RLHF projects.
- Fully remote, part-time, project-based consulting engagement focused on application security and vulnerability research.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×