Remote | CVE Vulnerability Researcher — $60–$80/hour

24-Mag Llc

Northern (KY)

Hybrid

USD 83,000 - 110,000

Part time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

24-MAG LLC is seeking a part-time vulnerability research consultant for CVE analysis, vulnerability reproduction, and secure remediation tasks. You will review CVE-based scenarios, lab environments, and safety of dockerized labs, providing rubric-based technical feedback.

The ideal candidate has 3+ years in application security or vulnerability research, with hands-on testing, strong written communication, and experience with Docker and CI/CD security controls. This remote role is US-focused.

Qualifications

  • 3+ years hands-on experience in application security, vulnerability research or penetration testing.
  • Demonstrated ability to evaluate CVE-based scenarios and provide precise technical feedback.
  • Experience reviewing vulnerability classifications and remediation strategies.

Responsibilities

  • Evaluate vulnerability-reproduction tasks based on documented CVEs.
  • Review CVE, CVSS, CWE, CAPEC taxonomy and risk rationale.
  • Assess remediation approaches for root-cause fixes and regression risks.
  • Review verification logic and ensure reproducibility of tests in Docker-based labs.

Skills

3+ years security experience
Security testing
Vulnerability research
Technical feedback

Education

OSCP GPEN GWAPT (adv.)

Tools

Docker
Docker Compose

Job description

We are sharing a specialised part-time consulting opportunity for experienced vulnerability researchers and application security professionals with strong expertise in CVE analysis, vulnerability reproduction, secure remediation, and security testing.

This role focuses on evaluating vulnerability-reproduction and remediation tasks for technical accuracy, realism, completeness, and verification quality. Selected experts will review CVE-based scenarios, proposed fixes, security test logic, and containerised lab environments while providing clear, rubric-based technical feedback.

Key Responsibilities
CVE & Vulnerability Review
  • Evaluate vulnerability-reproduction tasks based on documented CVEs
  • Assess whether scenarios faithfully represent the underlying vulnerability
  • Review technical assumptions, affected components, and expected behaviour
  • Identify incomplete, inaccurate, or unrealistic reproductions
  • Apply practical judgement grounded in hands-on vulnerability research or application security experience
Vulnerability Classification
  • Review security issues using established vulnerability taxonomies
  • Apply frameworks such as CVE, CVSS, CWE, and CAPEC
  • Assess vulnerability classification and severity rationale
  • Identify incorrect or misleading categorisation
  • Evaluate whether reported security impact is supported by the technical evidence
Application Security & Remediation
  • Review proposed fixes for common application and system vulnerabilities
  • Assess remediation approaches involving issues such as SQL injection, command injection, buffer overflow, insecure deserialisation, SSRF, misconfigurations, and privilege escalation
  • Determine whether fixes address the underlying security issue rather than only its symptoms
  • Identify regressions or functionality problems introduced by remediation
  • Evaluate secure coding approaches for technical soundness
Verification & Security Testing
  • Review verification logic used to confirm vulnerability remediation
  • Evaluate paired functionality tests and vulnerability-focused tests
  • Assess whether tests demonstrate both preserved application behaviour and removal of the security weakness
  • Identify incomplete coverage or misleading validation
  • Determine whether verification criteria are sufficiently rigorous and reproducible
Docker-Based Security Labs
  • Review vulnerability reproduction environments built with Docker and Docker Compose
  • Assess whether multi-container environments accurately reproduce required conditions
  • Evaluate configuration, dependencies, networking, and service interactions
  • Identify environmental issues that could affect reproducibility
  • Review whether lab environments support consistent security evaluation
Technical Reproduction & QA
  • Assess whether security scenarios can be reproduced reliably
  • Review setup instructions, dependencies, configurations, and expected outcomes
  • Identify missing assumptions or inconsistencies affecting repeatability
  • Evaluate whether task scope is appropriate and technically complete
  • Distinguish environment defects from genuine security findings
Secure Development Review
  • Evaluate application changes from a secure-coding perspective
  • Identify incomplete or fragile remediation strategies
  • Review whether security fixes maintain intended application functionality
  • Assess code and configuration changes for security implications
  • Apply practical application-security judgement across different vulnerability classes
Security Tooling & Engineering Workflows
  • Review workflows involving secure development and vulnerability assessment
  • Apply familiarity with SAST, DAST, CI/CD security controls, and DevSecOps practices where relevant
  • Assess whether security checks are appropriately integrated into development processes
  • Identify gaps in validation or security gating
  • Evaluate security engineering recommendations for practical effectiveness
Rubric-Based Technical Evaluation
  • Assess assigned security tasks against structured technical criteria
  • Provide clear written explanations supporting evaluation decisions
  • Reference specific reproduction, remediation, testing, or configuration evidence
  • Apply evaluation standards consistently across assignments
  • Distinguish valid alternative security approaches from technically flawed solutions
Ideal Profile
  • 3+ years of hands-on experience in application security, penetration testing, or vulnerability research
  • Strong understanding of CVE vulnerability taxonomy and severity frameworks
  • Practical knowledge of CVSS, CWE, and CAPEC
  • Strong secure-coding and remediation experience across common vulnerability classes
  • Experience reviewing or designing security verification logic
  • Proficiency with Docker and Docker Compose
  • Strong ability to evaluate whether vulnerability reproductions and remediation approaches are technically sound
  • Experience with responsible vulnerability disclosure or CVE reporting is advantageous
  • Experience maintaining security proof-of-concept code is advantageous
  • Background in DevSecOps, CI/CD security gating, SAST, or DAST tooling is preferred
  • Certifications such as OSCP, GPEN, GWAPT, or equivalent are advantageous
  • Previous technical review, security assessment design, or QA experience is preferred
  • Strong written communication and ability to provide precise technical feedback
Engagement Details
  • Part-time independent contractor engagement
  • Fully remote within the United States
  • Flexible scheduling based on project requirements
  • Compensation: $60–$80/hour
  • Work focuses on CVE analysis, vulnerability reproduction, secure remediation, verification logic, and security task evaluation
  • Projects may be extended, shortened, or concluded based on project needs and performance
  • Work must be completed without using confidential or proprietary information belonging to any employer, client, institution, or other third party
  • H1-B and STEM OPT support is unavailable for this engagement
About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Part-Time CVE Vulnerability Researcher
Remote Part-Time CVE Vulnerability Researcher

24-Mag Llc • Northern (KY)

Hybrid
USD 83,000 - 110,000
Vulnerability Analyst | $90/hr Remote
Vulnerability Analyst | $90/hr Remote

Crossing Hurdles • United States

On-site
USD 41,328 - 123,984
CVE Vulnerability Expert
CVE Vulnerability Expert

HumanitApp • Northern (KY)

Hybrid
USD 96,000 - 124,000
CVE Vulnerability Expert Mercor · Remote — United States $70-90/hr →
CVE Vulnerability Expert Mercor · Remote — United States $70-90/hr →

Dorado • Northern (KY)

Hybrid
USD 100,000 - 140,000
Remote Vulnerability Analyst & Penetration Tester
Remote Vulnerability Analyst & Penetration Tester

Crossing Hurdles • United States

On-site
USD 41,328 - 123,984
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

Hybrid
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Vulnerability Management Engineer
Vulnerability Management Engineer

WideNet Consulting Group • Seattle (WA)

Hybrid
USD 103,000 - 117,000
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Charlotte (NC)

On-site
USD 80,000 - 100,000
Vulnerability Analyst
Vulnerability Analyst

Delan Associates, Inc • Lemont (IL)

Remote
USD 75,000 - 95,000
Flexible work schedule
Government-furnished laptop
Remote Vulnerability Analyst — Cyber Hygiene & Risk Assessments
Remote Vulnerability Analyst — Cyber Hygiene & Risk Assessments

Boston Government Services, LLC (BGS) • Knoxville (TN)

On-site
USD 85,000 - 110,000