Vulnerability Reproduction and Fix Reviewer
REMOTE
il y a 1 jour
Work you will do
- Reproduce the relevant CVE in an authorized, isolated environment and establish a reliable demonstration of the defect.
- Review vulnerability classification, severity assumptions and Docker or repository setup so the task measures the intended security problem.
- Test the remediation and document why it fixes the issue without relying on a misleading or overly narrow verifier.
Required background and routes
- At least three years in application security, vulnerability research or penetration testing; understand CAPEC, CWE and CVSS classifications.
- Evaluate remediation for issues such as SSRF, deserialization, buffer overflows, injection, privilege escalation and insecure configuration. Verify both preserved functionality and removal of the vulnerability.
- Build or assess multi-container reproduction environments with Docker Compose and Docker.
Preferred background
- GWAPT, GPEN, OSCP or equivalent; responsible disclosure or CVE work, maintained proof-of-concept code, CI security gates, SAST/DAST, DevSecOps or security assessment authoring.
Deliverables
- Submit the completed technical artifact or assessment with its supporting evidence, explicit assumptions, reproducible checks where applicable, and concise reasons for each material judgment.
- Address review findings within the agreed scope.
Location and schedule
Regional eligibility: United States. Remote assignments are scheduled by agreement, with no guaranteed weekly volume. Availability planning can include 40 hours per week depending on the track. IXO confirms the applicable timing before work.
Pay and working terms
$75 $95/hr USD. The agreed hourly rate, scope, schedule and acceptance criteria are confirmed before work starts. Applying does not guarantee an assignment. Use public, licensed or otherwise authorized material only; do not submit confidential employer information, personal data or restricted research. Security and safety testing stays within the expressly authorized evaluation environment.
#J-18808-Ljbffr
Entreprise
ixolabs.ai
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
REMOTE
il y a 1 jour
REMOTE
il y a 1 jour
REMOTE
il y a 1 jour
REMOTE
il y a 1 jour