Expert en recherche en cybersécurité, sécurité offensive et recherche de vulnérabilités
200 $US à 250 $US/hFourchette indicative communiquée par Mercor
Publié le 4 août 2026 · Candidatures jusqu'au 18 octobre 2026
Je vous redirige vers la page officielle de Mercor. La candidature est gratuite et se fait en anglais.
Je touche une commission de la plateforme si un candidat que j'ai orienté est recruté. Cela ne change rien pour vous.
L'expert en recherche en cybersécurité évalue les analyses générées par l'intelligence artificielle concernant des exploits complexes et valide l'analyse des causes profondes des vulnérabilités. Les candidats doivent présenter un solide parcours en recherche en sécurité offensive, incluant une expérience dans des compétitions de type CTF de premier plan, des vulnérabilités CVE découvertes ou des signalements de primes de bugs reconnus.
Description en anglais, telle que publiée par Mercor.
We're looking for highly accomplished Cybersecurity Research Experts to help evaluate cutting-edge AI systems in advanced security reasoning, vulnerability analysis, exploit development, and secure software engineering. This project is ideal for practitioners with a strong track record in offensive security research and publicly recognised technical contributions.
What You'll Do
-
Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
-
Review technical writeups for correctness, exploitability, and mitigation quality.
-
Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
-
Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
-
Contribute to benchmark development for advanced AI security capabilities.
Ideal Background
We are looking for candidates with multiple of the following credentials:
-
Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
-
Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
-
Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
-
Research experience at a well-respected security laboratory or academic research group (e.g., KAIST Security Lab, SSLab, university security research groups, or equivalent industry research organisations).
-
Author of high-quality security research publications, conference papers, or widely cited technical writeups.
-
Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred Qualifications
-
Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
-
Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
-
Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
-
Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
-
Strong programming skills in C/C++, Rust, Python, Go, or Java.
-
Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
-
Hall of Fame recognition from major bug bounty programs.
-
Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
-
Maintainer or significant contributor to well-known open-source security tools.
-
Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Why Join?
-
Work on frontier AI models tackling real-world cybersecurity problems.
-
Collaborate with leading researchers on advanced security evaluation tasks.
-
Help shape the next generation of AI systems for cybersecurity.
À propos de Mercor
Mercor est une place de marché américaine qui recrute des experts à distance pour des projets d'IA et de conseil, du droit à l'ingénierie. L'offre originale est consultable sur leur site.
Voir l'offre sur MercorAutres postes en Développement logiciel
Responsable d'ingénierie Python, entraînement et évaluation de LLM
Ce poste indépendant à distance consiste à diriger de grandes équipes d'ingénieurs Python et de data scientists pour soutenir l'entraînement et l'évaluation des LLM fondamentaux. Les candidats doivent justifier d'au moins cinq ans d'expérience en génie logiciel, d'une solide maîtrise de Python et de compétences avérées en gestion.
- Python
- Software Development
Publié hier
Expert sectoriel - Ingenierie
Ce role distant consiste a batir des fonctionnalites front-end evolutives avec React et JavaScript. Les candidats ont besoin d'au moins trois annees d'experience en tant qu'ingenieur front-end et d'un diplome en informatique ou equivalent.
- Data Engineering
Publié il y a 2 j
Contributeur open source (GitHub)
Le contributeur open source explore, débogue et modifie des composants front-end et back-end pour un projet d'entraînement en IA. Les candidats ont besoin d'un profil GitHub vérifiable avec des contributions open source significatives et d'une solide expérience en génie logiciel dans plusieurs langages de programmation.
- Python3
- JAVA
- Rust
- +3
Publié il y a 2 j100 $US à 150 $US/h
Ingénieur logiciel full stack senior
L'ingénieur logiciel full stack senior conçoit, débugue et évalue des composants d'application front end et back end pour un projet de formation en IA. Le poste requiert une solide expérience professionnelle dans le développement d'applications full stack destinées à la production ainsi qu'une expertise pratique sur plusieurs langages de programmation.
- Python
- React
- JavaScript
- +5
Publié il y a 2 j50 $US à 100 $US/h