Anyone AI
Anyone AI
Anyone AI is a Latin America–focused education and talent platform helping software engineers develop careers in artificial intelligence and machine learning. Its remote, mentor-led programs combine technical training, including a Machine Learning Developer track, with career preparation such as resume and LinkedIn guidance, interview coaching, and English practice. The company also operates a talent marketplace that connects its trained community with employers seeking AI professionals, alongside a placement-oriented model that includes income-share payments and employer partnerships.

Senior Application Security Engineer, CVE Research (Argentina Remote)

Research CVE reproductions and exploit paths for Anyone AI, then assess remediation through Docker labs and security regression tests. This remote, part-time role is based in Argentina.

Description

  • Review application security tasks covering CVE reproduction, exploit proof-of-concepts, remediation, secure coding, Docker labs, and regression testing.
  • Check whether vulnerability environments recreate the original attack conditions.
  • Assess whether proposed fixes address vulnerabilities while preserving legitimate functionality.
  • Verify the technical accuracy of CVE reproduction environments.
  • Assess proposed security fixes and remediation approaches.
  • Review test suites to confirm normal functionality remains intact and the original exploit no longer works.
  • Find incomplete fixes and alternative exploitation paths.
  • Check Docker environments for accurate software versions, services, networking, and configuration.
  • Identify regressions or new vulnerabilities caused by fixes.
  • Recommend improvements to vulnerability reproductions, fixes, and verification logic.

Requirements

  • At least 3 years of practical experience in application security, penetration testing, or vulnerability research.
  • Strong knowledge of CVEs, CVSS, CWE, and common vulnerability classes.
  • Experience finding and remediating SQL injection, command injection, SSRF, deserialization flaws, buffer overflows, privilege escalation, access control issues, and security misconfigurations.
  • Strong knowledge of secure coding and vulnerability remediation.
  • Experience reviewing or creating exploit proof-of-concepts.
  • Experience checking whether security fixes resolve root causes.
  • Proficiency with Docker and Docker Compose.
  • Able to provide clear, technically rigorous written feedback.
  • OSCP, GPEN, GWAPT, or an equivalent security certification is a plus.
  • Experience with responsible vulnerability disclosure or CVE reporting is a plus.
  • Experience maintaining exploit proof-of-concept code is a plus.
  • Experience writing automated security tests using Python, requests, curl, pwntools, or custom exploit harnesses is a plus.
  • DevSecOps experience is a plus.
  • Familiarity with SAST, DAST, and CI/CD security tools is a plus.
  • Experience developing or reviewing cybersecurity assessments or technical security challenges is a plus.
  • Experience with AI evaluation, RLHF, or technical data projects is a plus.

Benefits

  • Remote work.
  • Part-time, project-based consulting engagement.
  • Hourly compensation of $65.

Related Jobs

Knowtion Health

Remote Talent Acquisition Manager

Knowtion Health

Oversee recruiting systems, requisitions, analytics, and contingent workforce operations at Knowtion Health. Help support scalable hiring processes for a growing healthcare company.

Open