← Zurück zur Liste
Stelle · Senior

Cybersecurity Expert - Offensive Security

Security Engineer • Senior • Remote • Vollzeit Deutschland Deutschland

Mercor is hiring a Cybersecurity Research Expert in offensive security and vulnerability research to evaluate AI-generated cybersecurity analyses and validate exploit chains. Candidates review technical writeups, vulnerability root-cause analyses and defensive recommendations to help build benchmarks for advanced AI security capabilities. It's a high-paying remote contract role for senior security researchers.

Responsibilities

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits and vulnerability reports
  • Review technical writeups for correctness, exploitability and mitigation quality
  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud and web applications
  • Provide structured feedback on security reasoning, exploit chains and defensive recommendations
  • Contribute to benchmark development for advanced AI security capabilities

Requirements

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements
  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software
  • Publicly recognised bug bounty researcher with findings accepted by major programs
  • Research experience at a respected security laboratory or academic research group
  • Author of security research publications, conference papers or widely cited technical writeups
  • Strong understanding of exploit development, reverse engineering, binary analysis or cryptography

Nice to have

  • Professional experience in offensive security, application security, vulnerability research or product security
  • Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja or Radare2
  • Familiarity with fuzzing, symbolic execution, static or dynamic analysis frameworks
  • Experience with Linux internals, Windows internals, browser, cloud, embedded or mobile security
  • Strong programming skills in C/C++, Rust, Python, Go or Java
  • Hall of Fame recognition from major bug bounty programs
  • Conference presentations or publications at Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS or NDSS
  • Maintainer or significant contributor to well-known open-source security tools
  • Offensive Security (OSCP, OSEP, OSCE3) or GIAC certifications

Soft skills

Excellent written communicationAbility to explain complex security concepts clearlyIndependent, asynchronous work style

What we offer

  • Compensation of $200-250 per hour
  • Fully remote, contract engagement

About the company

Mercor connects elite creative and technical talent with leading AI research labs; it is headquartered in San Francisco and backed by investors including Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers and Jack Dorsey.

Ähnliche Stellen