hirly

Anyone AI

Application Security Engineer – CVE & Vulnerability Research

Argentina - Fully Remote · Uruguay · Chile · Ecuador - Fully Remote · Portugal · Mexico - Fully Remote · Colombia - Fully Remote · Spain · Brazil

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Anyone AI first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Countries
AR, UY, CL, EC, PT, MX, CO, ES, BR
Work mode
Remote-friendly
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Anyone AI is recruiting experienced Application Security Engineers and Vulnerability Researchers for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments.

We’re looking for security professionals with hands-on experience in penetration testing, vulnerability research, or application security who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated.

What You’ll Work On

You’ll review technical security tasks involving:

CVE vulnerability reproduction

Exploit proof-of-concepts

Vulnerability remediation and secure coding

Application security testing

Docker-based vulnerability labs

Exploit verification scripts

Security regression testing

CVSS, CWE, and vulnerability classification

Environment and configuration analysis

Edge cases and alternative attack paths

A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality.

What We’re Looking For

3+ years of hands-on experience in application security, penetration testing, or vulnerability research

Strong understanding of CVE, CVSS, CWE, and common vulnerability classes

Experience identifying and remediating vulnerabilities such as:

SQL injection

Command injection

SSRF

Deserialization vulnerabilities

Buffer overflows

Privilege escalation

Access control issues

Security misconfigurations

Strong understanding of secure coding and vulnerability remediation

Experience reviewing or developing exploit proof-of-concepts

Experience validating whether security fixes address the root cause rather than only the immediate exploit

Proficiency with Docker and Docker Compose

Ability to provide clear, technically rigorous written feedback

What You’ll Be Responsible For

Reviewing CVE reproduction environments for technical accuracy

Determining whether vulnerabilities faithfully reproduce the original attack vector and impact

Evaluating proposed security fixes and remediation strategies

Reviewing test suites that verify both:

Normal application functionality remains intact

The original exploit no longer succeeds

Identifying incomplete fixes and alternative exploitation paths

Reviewing Docker environments for correct software versions, services, networking, and configuration

Detecting potential regressions or new vulnerabilities introduced by a fix

Providing recommendations for improving vulnerability reproductions, fixes, and verification logic

Nice to Have

OSCP, GPEN, GWAPT , or equivalent security certification

Experience with responsible vulnerability disclosure or CVE reporting

Experience maintaining exploit proof-of-concept code

Experience writing automated security tests using tools such as:

Python

requests

curl

pwntools

Custom exploit harnesses

DevSecOps experience

Familiarity with SAST, DAST, and CI/CD security tooling

Experience developing or reviewing cybersecurity assessments or technical security challenges

Experience with AI evaluation, RLHF, or technical data projects

Engagement

  • Work Type: Remote
  • Engagement: Part-time, project-based consulting
  • Focus: Application security, vulnerability research, CVE reproduction, and remediation

This role is ideal for security engineers who enjoy understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.

Original posting on Anyone AI's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job