Security Engineer, Application Security

Mercor

Not Interested
Bookmark
Report This Job

profile Job Location:

San Francisco, CA - USA

profile Monthly Salary: $ 130 - 500
Posted on: Yesterday
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

About Mercor

Mercor is defining the future of work. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge experience and context that cant be captured in code alone. Today more than 30000 experts in our network collectively earn over $2 million a day.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious fast-paced and deeply committed team. Youll work alongside researchers operators and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco NYC or London offices.

Youll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. Youll embed in the development lifecycle review code for exploitable flaws build security tooling into CI/CD and drive vulnerability remediation across a platform serving 300K experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools using LLMs to accelerate code review and threat modeling and automating away the repetitive work that slows AppSec programs down. If youd rather write a CodeQL query than file a Jira ticket youll fit in here.

Were in-person five days a week at our SF headquarters with first Fridays remote.

What Youll Build:

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs injection flaws and business logic errors before they ship

  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys

  • Vulnerability management processes that prioritize by real exploitability not CVSS score

  • Secure coding standards and guardrails that make the safe path the easy path for 50 engineers

  • Threat models for new features and architecture changes - especially around AI data pipelines payment flows and multi-tenant boundaries

  • Bug bounty program operations - triaging HackerOne reports validating findings and driving fixes to closure

What Were Looking For

  • Youve found and fixed real vulnerabilities in production applications - not just run scanners

  • Deep understanding of web application security: OWASP Top 10 is baseline you think in terms of attack chains and business logic flaws

  • Strong in at least one of Python TypeScript or Go - you can read a PR and spot the auth bypass

  • Experience building or tuning SAST/DAST tooling (Semgrep CodeQL Snyk Burp or similar)

  • You understand modern web frameworks APIs and authentication patterns well enough to threat model them

  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation

  • 5 years of professional experience in application security security engineering or software engineering with a strong security focus

Bonus Points

  • Experience running or triaging a bug bounty program (HackerOne Bugcrowd)

  • Offensive security skills - youve done penetration testing and can think like an attacker

  • Experience securing AI/ML applications - model serving APIs training data pipelines prompt injection defense

  • Familiarity with supply chain security - dependency scanning registry firewalls (Socket Snyk)

  • Youve built custom security tooling that a team still uses

  • Contributions to open source security projects or published vulnerability research

Why Mercor

  • The problem is real. Application security at scale is hard - youll build defenses that matter across a fast-moving platform.

  • AI-native AppSec. Youll use frontier AI tools daily - for code review vulnerability analysis and anything that benefits from an AI co-pilot.

  • Ownership from day one. Youll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.

  • See the future early. Working alongside AI labs means youll understand frontier model capabilities months before the market.

Benefits

  • Equity ownership in a high-growth profitable company

  • Relocation support to San Francisco NYC or London as needed

  • Housing support near our SF office

  • Daily meal stipend

  • Premium fitness membership at Equinox

  • Comprehensive health insurance


Required Experience:

IC

About MercorMercor is defining the future of work. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge experience and context tha...
View more view more

About Company

Company Logo

Find top-tier, remote, AI roles for your expertise. Available only on Mercor.

View Profile View Profile