CYBERSECURITY EXPERT - OFFENSIVE SECURITY
mercor
Part-timemid€200-250/hour
Job description
About the job
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey .
Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type: Contract
Compensation: $200–$250/hour
Location: Remote
Role Responsibilities
• Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
• Review technical writeups for correctness, exploitability, and mitigation quality.
• Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
• Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
• Contribute to benchmark development for advanced AI security capabilities .
• Work independently and asynchronously to meet deadlines while improving AI model performance .
Qualifications
Must-Have
• Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
• Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
• Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
• Research experience at a well-respected security laboratory or academic research group .
• Author of high-quality security research publications , conference papers, or widely cited technical writeups.
• Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred
• Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
• Experience with reverse engineering tools such as IDA Pro , Ghidra , Binary Ninja , or Radare2 .
• Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
• Experience with Linux internals , Windows internals , browser security, cloud security, embedded security, or mobile security.
• Strong programming skills in C/C++ , Rust , Python , Go , or Java .
• Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
• Hall of Fame recognition from major bug bounty programs.
• Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
• Maintainer or significant contributor to well-known open-source security tools.
• Offensive Security certifications ( OSCP , OSEP , OSCE3 ), GIAC certifications , or equivalent credentials.
Application Process (Takes 20–30 mins to complete)
• Upload resume
• AI interview based on your resume
• Submit form
Resources & Support
• For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
• For any help or support, reach out to: support@mercor.com
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Skills
IDA ProGhidraBinary NinjaRadare2C/C++RustPythonGoJavaOSCPOSEPOSCE3GIAC certifications