About The Job Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey .
Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type: Contract Compensation: $200–$250/hour Location: Remote Role Responsibilities
- Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
- Review technical writeups for correctness, exploitability, and mitigation quality.
- Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
- Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
- Contribute to benchmark development for advanced AI security capabilities.
- Work independently and asynchronously to meet deadlines while improving AI model performance.
Qualifications Must-Have
- Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
- Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
- Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
- Research experience at a well-respected security laboratory or academic research group.
- Author of high-quality security research publications, conference papers, or widely cited technical writeups.
- Strong understanding of exploit development,
reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
Preferred
- Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
- Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
- Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
- Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
- Solid programming skills in C/C++, Rust, Python, Go, or Java.
- Excellent written communication and ability to explain complex security concepts clearly.
Nice to Have
- Hall of Fame recognition from major bug bounty programs.
- Black Hat, DEF CON, USENIX Security, IEEE S&P;, ACM CCS, NDSS, or similar conference presentations/publications.
- Maintainer or significant contributor to well-known open-source security tools.
- Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.
Application Process (Takes 20–30 mins to complete)
- Upload resume
- AI interview based on your resume
- Submit form
Resources & Support
- For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
- For any help or support, reach out to:
[email protected]
PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity. ,
📌 Cybersecurity Expert - Offensive Security (India)
🏢 Mercor
📍 India