Chargement en cours

Vulnerability Reproduction and Fix Reviewer

REMOTE
il y a 1 jour

Work you will do

  • Reproduce the relevant CVE in an authorized, isolated environment and establish a reliable demonstration of the defect.
  • Review vulnerability classification, severity assumptions and Docker or repository setup so the task measures the intended security problem.
  • Test the remediation and document why it fixes the issue without relying on a misleading or overly narrow verifier.

Required background and routes

  • At least three years in application security, vulnerability research or penetration testing; understand CAPEC, CWE and CVSS classifications.
  • Evaluate remediation for issues such as SSRF, deserialization, buffer overflows, injection, privilege escalation and insecure configuration. Verify both preserved functionality and removal of the vulnerability.
  • Build or assess multi-container reproduction environments with Docker Compose and Docker.

Preferred background

  • GWAPT, GPEN, OSCP or equivalent; responsible disclosure or CVE work, maintained proof-of-concept code, CI security gates, SAST/DAST, DevSecOps or security assessment authoring.

Deliverables

  • Submit the completed technical artifact or assessment with its supporting evidence, explicit assumptions, reproducible checks where applicable, and concise reasons for each material judgment.
  • Address review findings within the agreed scope.

Location and schedule

Regional eligibility: United States. Remote assignments are scheduled by agreement, with no guaranteed weekly volume. Availability planning can include 40 hours per week depending on the track. IXO confirms the applicable timing before work.

Pay and working terms

$75 $95/hr USD. The agreed hourly rate, scope, schedule and acceptance criteria are confirmed before work starts. Applying does not guarantee an assignment. Use public, licensed or otherwise authorized material only; do not submit confidential employer information, personal data or restricted research. Security and safety testing stays within the expressly authorized evaluation environment.

#J-18808-Ljbffr
Entreprise
ixolabs.ai
Plateforme de publication
WHATJOBS
Soyez le premier à postuler aux nouvelles offres
Soyez le premier à postuler aux nouvelles offres
Créez gratuitement et simplement une alerte pour être averti de l’ajout de nouvelles offres correspondant à vos attentes.
* Champs obligatoires
Ex: boulanger, comptable ou infirmière
Alerte crée avec succès