About OpenTrain OpenTrain is the centralized, open platform where AI training and data-labeling freelancers find work, consolidate opportunities across platforms, and build a unified AI training portfolio they control. We make specialized AI training work easier to track, apply for, and grow into a durable freelance career.
About this role OpenTrain is recruiting for a CVE Vulnerability Evaluation Expert role. In this position, you will evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks that are used to train and evaluate a frontier AI lab's models. You will assess whether CVE reproductions are faithful, fixes are sound, verification logic is rigorous, and Docker-based lab environments accurately recreate exploitable conditions, providing clear, rubric-based written feedback on each task.
What you will do - Assess the faithfulness of CVE reproductions and the soundness of proposed fixes - Evaluate verification logic to ensure it rigorously tests both functionality and vulnerability - Review Docker-based lab environments for accurate recreation of exploitable conditions - Provide rubric-based written feedback on the quality, fidelity, and completeness of each task - Identify areas for improvement in vulnerability-reproduction and remediation workflows
Required skills - 3+ years of hands-on experience in application security, penetration testing, or vulnerability research - Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC) - Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation) - Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests) - Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments
Helpful background - OSCP, GPEN, GWAPT, or equivalent offensive-security certification - Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code - Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling - Prior technical content review, assessment design, or QA for security-focused engineering tasks
Review AI-generated documents, spreadsheets, and presentations for cybersecurity and IT GRC quality, accuracy, and clarity. Work remotely for $80-$120 per hour with a flexible 20+ hour weekly engagement.
Evaluate GPU and accelerator kernel tasks for correctness, performance, compilation, and runtime validity. This fully remote US contract role pays $70 to $90 per hour and requires expertise across CUDA, Triton, NKI, or Pallas.
Probe conversational AI with jailbreaks, prompt injections, and multi-turn attacks while producing safety data and reproducible vulnerability reports. This remote contractor role supports 20+ hours per week at $48 to $62 per hour.