2

Vulnerability Researcher Remote Jobs in New York

next page

Showing results 1-20

Vulnerability Researcher Remote information

What does a vulnerability researcher do, especially in a remote role?

A Vulnerability Researcher is responsible for identifying, analyzing, and reporting security weaknesses in software, hardware, or network systems. Working remotely, they use specialized tools and techniques to discover vulnerabilities, assess potential impacts, and sometimes develop proof-of-concept exploits. Their findings help organizations improve security by patching vulnerabilities before they can be exploited by malicious actors. Effective communication and collaboration with security teams are also important aspects of the role, even when working from afar.

What are the key skills and qualifications needed to thrive as a vulnerability researcher remote, and why are they important?

To thrive as a Vulnerability Researcher (Remote), you need strong expertise in cybersecurity fundamentals, reverse engineering, and exploit development, typically supported by a degree in computer science or related certifications such as OSCP or CEH. Familiarity with technical tools like IDA Pro, Ghidra, fuzzers, debuggers, and scripting languages (e.g., Python) is essential for analyzing vulnerabilities. Analytical thinking, problem-solving, and effective communication are key soft skills that help in documenting findings and collaborating with distributed teams. These skills ensure the accurate identification and mitigation of security risks, which is crucial for protecting organizations against cyber threats.

What are some common challenges faced by remote vulnerability researchers and how can they be addressed?

Remote vulnerability researchers often encounter challenges such as staying current with rapidly evolving threat landscapes, maintaining effective communication with distributed teams, and accessing secure lab environments for testing. To address these, it's important to regularly engage in professional development, participate in virtual security communities, and utilize secure cloud-based lab solutions. Additionally, setting clear communication protocols and using collaboration tools can help ensure smooth teamwork and project progress.

What is the difference between Vulnerability Researcher Remote vs Penetration Tester Remote?

AspectVulnerability Researcher RemotePenetration Tester Remote
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, with emphasis on offensive security skills
Work EnvironmentResearch-focused, analyzing vulnerabilities in software and systemsSimulating attacks to identify security weaknesses
Industry UsageUsed in cybersecurity firms, tech companies, and research labsCommon in consulting firms, security service providers, and internal security teams
Search & Comparison IntentUnderstanding roles in vulnerability discovery and researchComparing offensive security roles and testing approaches

Vulnerability Researcher Remote and Penetration Tester Remote both focus on cybersecurity but differ in approach. Researchers analyze and discover vulnerabilities, while testers simulate attacks to evaluate security. Both roles require similar certifications and are employed in related industries, but their daily tasks and objectives vary.

What are popular job titles related to Vulnerability Researcher Remote jobs in New York?

For Vulnerability Researcher Remote jobs in New York, the most frequently searched job titles are:

What job categories do people searching Vulnerability Researcher Remote jobs in New York look for?

The top searched job categories for Vulnerability Researcher Remote jobs in New York are:

What cities in New York are hiring for Vulnerability Researcher Remote jobs?

Cities in New York with the most Vulnerability Researcher Remote job openings:

Cybersecurity Researcher - Fully Remote | Upto $250/hr

Mercor

New York, NY โ€ข Remote

$250/hr

Full-time

Posted 22 days ago


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type: Contract
Compensation: $200–$250/hour
Location: Remote

Role Responsibilities

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
  • Review technical writeups for correctness, exploitability, and mitigation quality.
  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
  • Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
  • Contribute to benchmark development for advanced AI security capabilities.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
  • Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
  • Research experience at a well-respected security laboratory or academic research group.
  • Author of high-quality security research publications, conference papers, or widely cited technical writeups.
  • Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.

Preferred

  • Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
  • Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
  • Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
  • Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
  • Strong programming skills in C/C++, Rust, Python, Go, or Java.
  • Excellent written communication and ability to explain complex security concepts clearly.

Nice to Have

  • Hall of Fame recognition from major bug bounty programs.
  • Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
  • Maintainer or significant contributor to well-known open-source security tools.
  • Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.