waypointjobs

Confidential

CVE Vulnerability Researcher for AI Model Evaluation

Berkeley, IL

Check who can apply and the requirements below before continuing.

About this opportunity

Confidential lists this CVE Vulnerability Researcher for AI Model Evaluation opportunity in Berkeley, Illinois. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Help strengthen AI security training by assessing vulnerability reproduction and remediation tasks for technical accuracy, realism, and completeness. You will evaluate CVE reproductions, proposed fixes, verification methods, and Docker-based lab environments, then provide clear written feedback using defined rubrics.

Key Responsibilities Review vulnerability reproduction and remediation tasks used to train and evaluate advanced AI models.

Assess whether CVE reproductions faithfully represent the underlying vulnerability and exploitable conditions.

Evaluate the soundness of remediation approaches and the rigor of verification logic.

Review Docker and Docker Compose environments to confirm they accurately recreate multi-container vulnerability scenarios.

Deliver clear, rubric-based written feedback on quality, fidelity, and completeness.

Qualifications 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.

Strong knowledge of CVE taxonomy and severity frameworks, including CVSS, CWE, and CAPEC.

Demonstrated secure-coding and remediation expertise across SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, and privilege escalation.

Experience designing or evaluating two-part verification approaches that include functionality tests and vulnerability tests.

Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Offensive-security certifications such as OSCP, GPEN, GWAPT, or an equivalent are preferred.

Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code is preferred.

Experience in DevSecOps, CI/CD security gating, SAST/DAST tooling, technical content review, assessment design, or QA for security-focused engineering tasks is preferred.

Work Terms Remote role, available to candidates located in the United States.

Hourly engagement.

Compensation $70 to $90 per hour.

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

True Oil LLC

WhatJobs

Tax manager

casper, WY

See pay details in description

This is a full-time, on-site position in Casper, Wyoming Salary: DOE, with a target of$150,000/annually. About Us: At True Oil LLC, we do more th…

Last received from source 2026-10-07View job

Intuit

WhatJobs

Tax expert - local tax office

palm beach gardens, FL

See pay details in description

Overview Intuit is seeking highly motivated individuals to join our dynamic team as dedicated year-round Turbo Tax Local Service Experts in one o…

Last received from source 2026-10-07View job

VCA Animal Hospitals

WhatJobs

Veterinary technician supervisor

long beach, CA

Salary: $23 - $32.75 per hour

If you are a hardworking individual looking to join a team of like-minded people with a passion for excellence in veterinary medicine, VCA Los Al…

Last received from source 2026-10-07View job

Intuit

WhatJobs

Tax expert - local tax office

charleston, AR

See pay details in description

Overview Intuit is seeking highly motivated individuals to join our dynamic team as dedicated year-round Turbo Tax Local Service Experts in one o…

Last received from source 2026-10-07View job