waypointjobs

Confidential

CVE Vulnerability Researcher for AI Model Evaluation

Wayne, IL

Check who can apply and the requirements below before continuing.

About this opportunity

Confidential lists this CVE Vulnerability Researcher for AI Model Evaluation opportunity in Wayne, Illinois. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Help strengthen AI security training by assessing vulnerability reproduction and remediation tasks for technical accuracy, realism, and completeness. You will evaluate CVE reproductions, proposed fixes, verification methods, and Docker-based lab environments, then provide clear written feedback using defined rubrics.

Key Responsibilities Review vulnerability reproduction and remediation tasks used to train and evaluate advanced AI models.

Assess whether CVE reproductions faithfully represent the underlying vulnerability and exploitable conditions.

Evaluate the soundness of remediation approaches and the rigor of verification logic.

Review Docker and Docker Compose environments to confirm they accurately recreate multi-container vulnerability scenarios.

Deliver clear, rubric-based written feedback on quality, fidelity, and completeness.

Qualifications 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.

Strong knowledge of CVE taxonomy and severity frameworks, including CVSS, CWE, and CAPEC.

Demonstrated secure-coding and remediation expertise across SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, and privilege escalation.

Experience designing or evaluating two-part verification approaches that include functionality tests and vulnerability tests.

Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.

Offensive-security certifications such as OSCP, GPEN, GWAPT, or an equivalent are preferred.

Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code is preferred.

Experience in DevSecOps, CI/CD security gating, SAST/DAST tooling, technical content review, assessment design, or QA for security-focused engineering tasks is preferred.

Work Terms Remote role, available to candidates located in the United States.

Hourly engagement.

Compensation $70 to $90 per hour.

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Mayo Clinic

WhatJobs

IV Technician

rochester, MN

See pay details in description

Why Mayo Clinic Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we w…

Last received from source 2026-10-08View job

First National Bank Texas

WhatJobs

Bilingual Personal Banker

port arthur, TX

Salary not specified

Job Description* Under direct supervision, provide exceptional customer service, involving receipt and payment of cash, while working in a high v…

Last received from source 2026-10-08View job

Sevita

WhatJobs

Direct Support Professional

kasson, MN

Wage $18.89 per hour

REM Community Services , a part of the Sevita family, provides community-based services for individuals with intellectual and developmental disa…

Last received from source 2026-10-08View job

Carmax, Carmax

WhatJobs

Auto Technician

leawood, KS

See pay details in description

7173 - Kansas City - 6801 E Frontage Rd, Merriam, Kansas, 66204 CarMax, the way your career should be!  Now offering a $7,500 Sign-On Bonus…

Last received from source 2026-10-08View job