Mercor
MercorVerified listing
RemoteCybersecurityAI & Machine Learning

Cybersecurity Research Expert – Offensive Security & Vulnerability Research | $200-$250/hr Remote

200–250/hr
Remote
Posted August 4, 2026
hourly
5 openings

Overview

Mercor is hiring experienced Cybersecurity Research Experts to test how well frontier AI models handle advanced security reasoning, vulnerability analysis, and exploit development. In this remote, hourly contract role, you'll review AI-generated security assessments, validate root-cause findings, and help build benchmarks that push AI security capabilities forward. This is a fit for practitioners with a strong track record in offensive security and a public portfolio of technical contributions.

What You'll Do5

  • 1Review AI-generated security analyses for technical accuracy, real-world exploitability, and completeness.
  • 2Assess technical writeups to confirm whether reported exploit paths are viable and whether suggested mitigations actually reduce risk.
  • 3Validate root-cause explanations for vulnerabilities across operating systems, networking, cloud environments, and web applications.
  • 4Deliver structured feedback on security reasoning, exploit chain logic, and the strength of defensive recommendations.
  • 5Contribute to the design and refinement of benchmarks that measure advanced security capabilities in AI systems.

Requirements8

  • 1A track record in offensive security research, backed by a mix of credentials from CTF competitions, CVE disclosures, and accepted bug bounty findings.
  • 2Publicly recognized contributions such as CVEs affecting widely used open-source or commercial software, or bug bounty results accepted by major programs like Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, or the Linux Foundation.
  • 3Research experience at a respected security lab, academic research group, or comparable industry organization, plus high-quality publications, conference papers, or widely cited technical writeups.
  • 4Working knowledge of exploit development, reverse engineering, binary analysis, and vulnerability research across operating systems, networks, web applications, or cryptography.
  • 5Hands-on familiarity with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2, and experience with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
  • 6Relevant professional experience in application security, product security, security engineering, or vulnerability research.
  • 7Strong programming ability in C/C++, Rust, Python, Go, or Java, along with clear technical writing skills.
  • 8Nice-to-have credentials include OSCP, OSEP, OSCE3, or GIAC certifications, conference presentations at Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, or NDSS, and contributions to well-known open-source security tools.

Who Should Apply

This role is for seasoned security researchers who have visible proof of their offensive security expertise — whether that's top-ranked CTF performance, authored CVEs, bug bounty hall-of-fame recognition, or published security research. You should be someone who enjoys pressure-testing AI-generated technical output, can explain complex security reasoning clearly in writing, and works well independently in a remote, project-based setup.

Salary Insight

Compensation is $200.00 - $250.00 per hour for this remote hourly engagement.

Location

Typeremote
LocationRemote
This is a remote position

Required Skills

offensive securityvulnerability researchexploit developmentreverse engineeringbinary analysisweb securitycryptographyfuzzingsymbolic executionstatic analysisdynamic analysisida-proghidraradare2linuxwindowscloud securitycpppythonrust

Application Tip

Make your proof of work impossible to miss: put CVE IDs, CTF team rankings, and named bug bounty programs at the top of your resume, and link to your talks, papers, or technical writeups. Concrete, verifiable contributions will set you apart far more than a generic credential list.

Share:

See NearSkill jobs more often in your search

How your application is processed

  1. 1Application received

    Your resume and details are logged the moment you apply.

  2. 2ATS + eligibility screening

    We check your profile against the role’s skills, seniority, and requirements.

  3. 3Employer sees qualified profiles only

    Only candidates who clear screening move forward.

See your fit score for every role

Similar open positions

Explore active roles that match your skills and interests.

Micro1

Micro1

1mo agoRemotecontract
Hot

Vulnerability Researcher and Staff Security Engineer

Remote role for a vulnerability researcher and staff-level security expert who operates as an internal adversary to uncover novel attack paths. You’ll study threats across AI agents, cloud infrastructure, developer platforms, and production systems, then collaborate with engineering to raise the stack’s resilience. Expect to build offensive tooling and publish internal research to shape security strategy. The position is full-time and focused on practical, hands-on security work in a remote setting. Bold Multi-Cloud, Red Teaming, AI security.

7–8/hr
Multi Cloud ExploitationRed TeamingStrategic Remediation+1 more
Micro1

Micro1

30d agoRemotecontract
Hot

Red Team Lead (Offensive Cybersecurity)

This remote contractor role with micro1 puts your offensive cybersecurity expertise to work in a unique way: you'll help train next-generation AI systems by designing evaluation frameworks and attack simulations. No prior AI experience is required—your hands-on knowledge of exploit chains, cloud/appsec, and social engineering is what makes you the ideal candidate. You'll shape how models learn about real-world threats while operating under strict ethical boundaries.

50–90/hr
Cyber SecurityExploit ChainsCloud/appsec+1 more
Mercor

Mercor

9d agoRemotehourly

CVE Vulnerability Expert

You will review vulnerability-reproduction and remediation assignments that feed the training and evaluation pipeline of a frontier AI lab. Each assignment asks you to judge whether CVE reproductions match the real-world flaw, whether the proposed fix actually eliminates the risk, and whether the verification logic can catch a regression. You will also inspect Docker Compose environments to confirm they recreate the exploitable condition described in the CVE. The output is a structured, rubric-based evaluation that shapes how the lab improves its model training data. The role is a remote, hourly engagement for security professionals based in the United States.

70–90/hr
· 3 openings
CveCvssCwe+15 more
Micro1

Micro1

30d agoRemotefull-time

Cyber Security Analyst

This role lets you put your cybersecurity expertise to work in a unique way—helping train next-generation AI systems. You won't need any prior AI experience; your domain knowledge in security is what counts. As a part-time, remote contractor, you'll test and guide AI models through hands-on prompts and analysis.

20–80/hr
· 6 openings
Threat DetectionNetwork SecurityPenetration Testing
Mercor

Mercor

30d agoRemotehourly

AI Safety Experts — English & Assamese

Mercor is assembling a remote red team of human experts to attack AI models with adversarial inputs. This role focuses on conversational AI, using native English and Assamese to probe for jailbreaks, prompt injections, and bias exploitation. You'll generate red team data and vulnerability reports that make AI systems safer for customers. The work is entirely text-based, with optional participation in higher-sensitivity projects supported by clear guidelines and wellness resources. Hourly compensation is $20-$22.

20–22/hr
· 10 openings
Red TeamingAdversarial Machine LearningJailbreak+16 more
Mercor

Mercor

1mo agoRemotehourly

AI Safety Experts — English & Norwegian

This remote role invites fluent English and Norwegian speakers to join an elite red team probing AI models for vulnerabilities. You'll simulate adversarial attacks, document exploits, and generate high-quality human data that directly strengthens AI safety. The work is text-based and focuses on sensitive topics like bias and misinformation, with optional high-sensitivity projects supported by clear guidelines.

48–62/hr
· 5 openings
EnglishNorwegianRed Teaming+14 more