Application Security Engineer – CVE & Vulnerability Research
Anyone Ai · Argentina - Fully Remote, Uruguay · posted Sep 15, 2026
Open to candidates in Argentina and Uruguay
What this role actually asks for
Extracted by RemoteHuntMust have
- •3+ years in appsec, pentesting, or vuln research
- •Strong understanding of CVE, CVSS, CWE
- •Experience with SQLi, Command Injection, SSRF, etc.
- •Proficiency with Docker and Docker Compose
- •Ability to provide clear, technically rigorous feedback
Nice to have
- •OSCP, GPEN, GWAPT certification
- •Experience with vulnerability disclosure
- •Experience writing automated security tests
- •DevSecOps experience
- •Familiarity with SAST, DAST, CI/CD security tooling
Tools and technologies
The full posting
Anyone AI is recruiting experienced Application Security Engineers and Vulnerability Researchers for a specialized project focused on reviewing real-world software vulnerabilities, CVE reproductions, remediation approaches, and exploit verification environments. We’re looking for security professionals with hands-on experience in penetration testing, vulnerability research, or application security who can determine whether vulnerabilities are reproduced accurately, fixes address the actual root cause, and security tests reliably demonstrate that an exploit has been mitigated.
What You’ll Work On You’ll review technical security tasks involving: CVE vulnerability reproduction Exploit proof-of-concepts Vulnerability remediation and secure coding Application security testing Docker-based vulnerability labs Exploit verification scripts Security regression testing CVSS, CWE, and vulnerability classification Environment and configuration analysis Edge cases and alternative attack paths A key part of the role is determining whether a vulnerability environment accurately recreates the original attack conditions and whether a proposed fix genuinely eliminates the vulnerability without breaking legitimate functionality.
What We’re Looking For 3+ years of hands-on experience in application security, penetration testing, or vulnerability research Strong understanding of CVE, CVSS, CWE, and common vulnerability classes Experience identifying and remediating vulnerabilities such as: SQL injection Command injection SSRF Deserialization vulnerabilities Buffer overflows Privilege escalation Access control issues Security misconfigurations Strong understanding of secure coding and vulnerability remediation Experience reviewing or developing exploit proof-of-concepts Experience validating whether security fixes address the root cause rather than only the immediate exploit Proficiency with Docker and Docker Compose Ability to provide clear, technically rigorous written feedback What You’ll Be Responsible For Reviewing CVE reproduction environments for technical accuracy Determining whether vulnerabilities faithfully reproduce the original attack vector and impact Evaluating proposed security fixes and remediation strategies Reviewing test suites that verify both: Normal application functionality remains intact The original exploit no longer succeeds Identifying incomplete fixes and alternative exploitation paths Reviewing Docker environments for correct software versions, services, networking, and configuration Detecting potential regressions or new vulnerabilities introduced by a fix Providing recommendations for improving vulnerability reproductions, fixes, and verification logic Nice to Have OSCP, GPEN, GWAPT , or equivalent security certification Experience with responsible vulnerability disclosure or CVE reporting Experience maintaining exploit proof-of-concept code Experience writing automated security tests using tools such as: Python requests curl pwntools Custom exploit harnesses DevSecOps experience Familiarity with SAST, DAST, and CI/CD security tooling Experience developing or reviewing cybersecurity assessments or technical security challenges Experience with AI evaluation, RLHF, or technical data projects Engagement Work Type: Remote Engagement: Part-time, project-based consulting Focus: Application security, vulnerability research, CVE reproduction, and remediation This role is ideal for security engineers who enjoy understanding how vulnerabilities actually work, reproducing exploits in controlled environments, evaluating security fixes, and identifying subtle gaps that traditional testing may miss.
Is this one actually worth your time?
RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.