> Markdown version of [/jobs/ext/2312832-application-security-specialist-fully-remote](https://www.wearedevelopers.com/jobs/ext/2312832-application-security-specialist-fully-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - Fully Remote - **Company:** Mercor, Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $145,600.0 - $187,200.0 - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Software System Penetration Testing, Continuous Integration, Machine Learning, Secure Coding, SQL Injection, Software Security, GWAPT, Devsecops, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 30, 2026 - **Apply:** https://www.careerjet.com/jobad/us6461e4c49821709df6a1118fc1208a7e ## About the Role Must-Have * 3+ years of hands-on experience in application security, penetration testing, or vulnerability research. * Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC). * Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation). * Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests). * Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments. Preferred * OSCP, GPEN, GWAPT, or equivalent offensive-security certification. * Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code. * Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling. * Prior technical content review, assessment design, or QA for security-focused engineering tasks. ## Description * Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training. * Assess CVE reproductions for faithfulness and ensure fixes are sound. * Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions. * Provide clear, rubric-based written feedback to improve model outputs. * Collaborate with AI research teams to enhance training data quality and downstream performance. * Work independently and asynchronously to meet deadlines while improving AI model performance., PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity., Customer Service Specialists work closely with wholesale and retail customers to determine their needs, answer their questions about Sherwin-Williams products, and recommend the ri… + 7 days ago ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)