Application Security Engineer – CVE & Vulnerability Research
anyone-ai
Argentina - Fully Remote
Posted Sep 15, 2026
- Contract
- Remote
- Software Engineering
Job description
Anyone AI is recruiting experienced **Application Security Engineers and Vulnerability Researchers** for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments. We’re looking for security professionals with hands-on experience in **penetration testing, vulnerability research, or application security** who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated. ## What You’ll Work On You’ll review technical security tasks involving: - CVE vulnerability reproduction - Exploit proof-of-concepts - Vulnerability remediation and secure coding - Application security testing - Docker-based vulnerability labs - Exploit verification scripts - Security regression testing - CVSS, CWE, and vulnerability classification - Environment and configuration analysis - Edge cases and alternative attack paths A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality. ## What We’re Looking For - **3+ years of hands-on experience** in application security, penetration testing, or vulnerability research - Strong understanding of **CVE, CVSS, CWE, and common vulnerability classes** - Experience identifying and remediating vulnerabilities such as: - SQL injection - Command injection - SSRF - Deserialization vulnerabilities - Buffer overflows - Privilege escalation - Access control issues - Security misconfigurations - Strong understanding of secure coding and vulnerability remediation - Experience reviewing or developing exploit proof-of-concepts - Experience validating whether security fixes address the root cause rather than only the immediate exploit - Proficiency with **Docker and Docker Compose** - Ability to provide clear, technically rigorous written feedback ## What You’ll Be Responsible For - Reviewing CVE reproduction environments for technical accuracy - Determining whether vulnerabilities faithfully reproduce the original attack vector and impact - Evaluating proposed security fixes and remediation strategies - Reviewing test suites that verify both: - Normal application functionality remains intact - The original exploit no longer succeeds - Identifying incomplete fixes and alternative exploitation paths - Reviewing Docker environments for correct software versions, services, networking, and configuration - Detecting potential regressions or new vulnerabilities introduced by a fix - Providing recommendations for improving vulnerability reproductions, fixes, and verification logic ## Nice to Have - **OSCP, GPEN, GWAPT**, or equivalent security certification - Experience with responsible vulnerability disclosure or CVE reporting - Experience maintaining exploit proof-of-concept code - Experience writing automated security tests using tools such as: - Python - `requests` - `curl` - pwntools - Custom exploit harnesses - DevSecOps experience - Familiarity with SAST, DAST, and CI/CD security tooling - Experience developing or reviewing cybersecurity assessments or technical security challenges - Experience with AI evaluation, RLHF, or technical data projects ## Engagement **Work Type:** Remote **Engagement:** Part-time, project-based consulting **Focus:** Application security, vulnerability research, CVE reproduction, and remediation This role is ideal for security engineers who enjoy **understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.**