For security engineers

Get paid to remediate real vulnerabilities.

We match organisations facing high-severity CVEs with vetted specialists who deliver reviewed, deployable fixes. If that’s you, join the roster — the vetting is a short quiz and a real technical assessment, read by people who do the work.

  • Project-based, remote, flexible
  • Assessment weighted over CV
  • Honest decisions with feedback
Why join

Serious work, on your terms

Real, paid engagements

Scoped remediation work with rates agreed up front — not spec work or unpaid trials.

Interesting problems

Work on high-severity, sometimes actively-exploited vulnerabilities that matter.

Flexible & remote

Choose the engagements you take, work from anywhere, at the pace you want.

A vetted network

Join a roster of practitioners who cleared the same real assessment you will.

Clear scope

Every engagement comes with a defined brief and a concrete deliverable.

Straightforward terms

Rates agreed before you start, and you deal with our team directly.

How vetting works

Four steps, no theatre

We read your assessment, not just your CV. Early-career applicants who nail the technical work are welcome.

1

Apply

Your profile, a short screening quiz, and a real technical assessment.

2

Assessment review

We read your patch and your reasoning — the work speaks louder than the résumé.

3

Decision

Onboard, waitlist, or decline — with honest, specific feedback.

4

Engagements

Matched to work that fits your specialisations and availability.

What we look for

The bar

  • Demonstrated remediation skill — the assessment carries the most weight.
  • Clear written communication: a fix nobody can follow isn’t a fix.
  • A verifiable track record — GitHub, public disclosures, assigned CVEs.
  • Judgment about safe, staged rollouts, not just a working patch.
FAQ

Common questions

Is this employment?

No — it’s project-based contract work. You take the engagements you choose to take.

How do I get paid?

Per engagement, at a rate agreed before you start. You invoice us directly.

Will you send me a real client’s systems or data?

The assessment here is a synthetic sample of our own. On real engagements you receive a scoped brief, and we’re deliberate about what client data is shared and how.

What happens after I apply?

We review your profile, your quiz result, and your assessment, then onboard, waitlist, or decline you with feedback.

Do I need to be available full-time?

No. Part-time and occasional availability are fine — tell us what suits you.

I’m early-career. Should I bother?

Yes. We weight the technical assessment heavily, so strong work counts for more than years on a CV.

Apply

Join the roster