Cybersecurity Research Expert, Offensive Security & Vulnerability Research
$200 to $250/hIndicative range provided by Mercor
Posted on August 4, 2026 · Applications until October 18, 2026
I am sending you to the official Mercor page. Applying is free and in English.
I earn a commission from the platform when a candidate I referred gets hired. It changes nothing for you.
The Cybersecurity Research Expert evaluates AI-generated analyses of complex exploits and validates vulnerability root-cause analysis. Candidates must have a strong track record in offensive security research, including top-ranked CTF experience, discovered CVEs, or recognized bug bounty findings.
Description in English, as published by Mercor.
We're looking for highly accomplished Cybersecurity Research Experts to help evaluate cutting-edge AI systems in advanced security reasoning, vulnerability analysis, exploit development, and secure software engineering. This project is ideal for practitioners with a strong track record in offensive security research and publicly recognised technical contributions.
What You'll Do
-
Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
-
Review technical writeups for correctness, exploitability, and mitigation quality.
-
Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
-
Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
-
Contribute to benchmark development for advanced AI security capabilities.
Ideal Background
We are looking for candidates with multiple of the following credentials:
-
Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
-
Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
-
Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
-
Research experience at a well-respected security laboratory or academic research group (e.g., KAIST Security Lab, SSLab, university security research groups, or equivalent industry research organisations).
-
Author of high-quality security research publications, conference papers, or widely cited technical writeups.
-
Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred Qualifications
-
Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
-
Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
-
Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
-
Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
-
Strong programming skills in C/C++, Rust, Python, Go, or Java.
-
Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
-
Hall of Fame recognition from major bug bounty programs.
-
Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
-
Maintainer or significant contributor to well-known open-source security tools.
-
Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Why Join?
-
Work on frontier AI models tackling real-world cybersecurity problems.
-
Collaborate with leading researchers on advanced security evaluation tasks.
-
Help shape the next generation of AI systems for cybersecurity.
About Mercor
Mercor is a US marketplace hiring remote experts for AI and consulting projects, from law to engineering. The original posting is on their site.
View this job on MercorMore jobs in Software engineering
Python Engineering Manager, LLM Training & Evaluation
This remote freelance role involves leading large teams of Python engineers and data scientists to support foundational LLM training and evaluation workflows. Candidates must have five or more years of software engineering experience with strong Python proficiency and proven management skills.
- Python
- Software Development
Posted yesterday
Domain Expert - Engineering
This remote role involves building scalable front end features using React and JavaScript. Candidates need at least three years of experience as a front end engineer and a degree in computer science or equivalent.
- Data Engineering
Posted 2 days ago
Open Source Contributor (GitHub)
The Open Source Contributor explores, debugs, and modifies front-end and back-end components for an AI training project. Applicants need a verifiable GitHub profile with meaningful open-source contributions and strong software engineering experience across multiple programming languages.
- Python3
- JAVA
- Rust
- +3
Posted 2 days ago$100 to $150/h
Sr. Full-Stack Software Engineer
The Senior Full Stack Software Engineer builds, debugs, and evaluates front end and back end application components for an AI training project. The role requires strong professional experience developing production full stack applications and hands on expertise across multiple programming languages.
- Python
- React
- JavaScript
- +5
Posted 2 days ago$50 to $100/h