← Back to list
Job · Senior

Cybersecurity Expert - Offensive Security

Security Engineer • Senior • Remote • Full-time • Germany Germany

Mercor is hiring a Cybersecurity Research Expert in offensive security and vulnerability research to evaluate AI-generated cybersecurity analyses and validate exploit chains. Candidates review technical writeups, vulnerability root-cause analyses and defensive recommendations to help build benchmarks for advanced AI security capabilities. It's a high-paying remote contract role for senior security researchers.

Responsibilities

  • ▹Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits and vulnerability reports
  • ▹Review technical writeups for correctness, exploitability and mitigation quality
  • ▹Validate vulnerability root-cause analysis across software, operating systems, networking, cloud and web applications
  • ▹Provide structured feedback on security reasoning, exploit chains and defensive recommendations
  • ▹Contribute to benchmark development for advanced AI security capabilities

Requirements

  • ▹Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements
  • ▹Discoverer or co-author of CVEs affecting widely used open-source or commercial software
  • ▹Publicly recognised bug bounty researcher with findings accepted by major programs
  • ▹Research experience at a respected security laboratory or academic research group
  • ▹Author of security research publications, conference papers or widely cited technical writeups
  • ▹Strong understanding of exploit development, reverse engineering, binary analysis or cryptography

Nice to have

  • ▹Professional experience in offensive security, application security, vulnerability research or product security
  • ▹Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja or Radare2
  • ▹Familiarity with fuzzing, symbolic execution, static or dynamic analysis frameworks
  • ▹Experience with Linux internals, Windows internals, browser, cloud, embedded or mobile security
  • ▹Strong programming skills in C/C++, Rust, Python, Go or Java
  • ▹Hall of Fame recognition from major bug bounty programs
  • ▹Conference presentations or publications at Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS or NDSS
  • ▹Maintainer or significant contributor to well-known open-source security tools
  • ▹Offensive Security (OSCP, OSEP, OSCE3) or GIAC certifications

Soft skills

Excellent written communicationAbility to explain complex security concepts clearlyIndependent, asynchronous work style

What we offer

  • ▹Compensation of $200-250 per hour
  • ▹Fully remote, contract engagement

About the company

Mercor connects elite creative and technical talent with leading AI research labs; it is headquartered in San Francisco and backed by investors including Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers and Jack Dorsey.

Similar jobs