Cybersecurity Expert - Offensive Security
Budget / Salary$200–250
TypeContract
LocationGermany
Posted8 hours ago
About the job
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.
Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type:Contract
Compensation:$200–$250/hour
Location:Remote
Role Responsibilities
Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
Review technical writeups for correctness, exploitability, and mitigation quality.
Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
Contribute to benchmark development for advanced AI security capabilities.
Work independently and asynchronously to meet deadlines while improving AI model performance.
Qualifications
Must-Have
Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
Research experience at a well-respected security laboratory or academic research group.
Author of high-quality security research publications, conference papers, or widely cited technical writeups.
Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred
Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
Strong programming skills in C/C++, Rust, Python, Go, or Java.
Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
Hall of Fame recognition from major bug bounty programs.
Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
Maintainer or significant contributor to well-known open-source security tools.
Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Application Process (Takes 20–30 mins to complete)
Upload resume
AI interview based on your resume
Submit form
Resources & Support
For details about the interview process and platform information, please check:
For any help or support, reach out to:
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Originally posted on Himalayas
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.
Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type:Contract
Compensation:$200–$250/hour
Location:Remote
Role Responsibilities
Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
Review technical writeups for correctness, exploitability, and mitigation quality.
Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
Contribute to benchmark development for advanced AI security capabilities.
Work independently and asynchronously to meet deadlines while improving AI model performance.
Qualifications
Must-Have
Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
Research experience at a well-respected security laboratory or academic research group.
Author of high-quality security research publications, conference papers, or widely cited technical writeups.
Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred
Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
Strong programming skills in C/C++, Rust, Python, Go, or Java.
Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
Hall of Fame recognition from major bug bounty programs.
Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
Maintainer or significant contributor to well-known open-source security tools.
Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Application Process (Takes 20–30 mins to complete)
Upload resume
AI interview based on your resume
Submit form
Resources & Support
For details about the interview process and platform information, please check:
For any help or support, reach out to:
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.