$70–90/hr · Mercor · Hourly, 40 hours a week
A security expert who evaluates the quality and accuracy of vulnerability training materials for AI model development.
What you would do
- Assess whether CVE reproductions faithfully demonstrate actual vulnerabilities and exploitable conditions
- Review remediation fixes to verify they eliminate vulnerabilities without introducing weaknesses
- Evaluate verification logic that combines functionality tests with security-specific vulnerability tests
- Verify Docker environments and configurations accurately recreate exploitable security scenarios
Who they want
- Minimum three years working directly in security assessments, threat research, or exploit development
- Strong knowledge of CVE taxonomy, CVSS scoring, CWE classification, and CAPEC frameworks
- Deep knowledge of secure coding practices and fix strategies covering common exploit vectors like injection, overflow, and privilege escalation
- Experience containerizing lab environments using Docker tooling to simulate vulnerable systems and demonstrate exploits
- Preferred: OSCP, GPEN, or GWAPT certification; CVE disclosure or responsible reporting background
Main skills
What the interview asks about
1.Reproducing vulnerability fidelity
The interviewer needs to verify you can distinguish between accurate and incomplete vulnerability reproductions, critical for evaluating AI training data quality.
For example: “A task claims to reproduce a server-side request forgery but only tests internal network access. The fix documentation shows remediation but doesn't address metadata leakage vectors. How would you score this CVE reproduction?”
2.Assessing remediation soundness
Security fixes must eliminate root causes without introducing new vulnerabilities; evaluating fix quality requires understanding threat models and attack patterns.
For example: “A SQL injection fix uses string concatenation with type checking instead of parameterized queries. The task's verification passes all tests. What's your assessment of this remediation approach?”
3.Designing comprehensive verification
Two-part verification logic must cover both normal operation and exploit attempts; spotting gaps in test coverage prevents flawed training data.
For example: “A buffer overflow task includes functionality tests showing the program runs correctly and security tests confirming overflow blocks the attack. What additional verification scenarios should you probe?”
4.Docker environment validation
Containerized labs must accurately simulate vulnerable systems; misconfigurations can mask or hide vulnerabilities, undermining model training.
For example: “A docker-compose setup for testing privilege escalation runs services with overly permissive capabilities. How would you evaluate whether this environment accurately demonstrates the vulnerability?”
5.CVE severity and classification
Proper classification using CVSS and CWE ensures training materials reflect real-world vulnerability severity and helps AI models prioritize risk appropriately.
For example: “A stored XSS vulnerability in a user profile field is rated CVSS 5.4 medium with no CWE linkage. The fix only escapes HTML output. Is the classification and remediation approach complete?”
A task you may get
Review a sample CVE reproduction task with Docker setup, proposed fix, and verification logic, providing rubric-based feedback on fidelity, remediation soundness, and test coverage.
How to prepare
- Review CVSS scoring framework and practice rating common vulnerability types
- Study recent CVE disclosures and remediation approaches across different vulnerability classes
- Practice designing two-part verification tests combining functionality and security validation
- Refresh Docker and container security concepts, particularly around privilege escalation and network isolation
The facts
- Pay
- $70–90/hr
- Hours
- Hourly, 40 hours a week
- Where
- Remote · Remote — United States
- Open to
- USA
- Field
- Software Engineering
- Posted
- 8/25/2026
- Places left
- 3
We wrote this page from the public Mercor listing. It may be out of date, so read the full posting before you apply.