Jobs Companies Mercor Security Engineer, Application Security

Über diese Security Engineer, Application Security Stelle bei Mercor

Mercor · Vor Ort · San Francisco

About Mercor

Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.

 

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.

You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.

We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build:

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship

  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys

  • Vulnerability management processes that prioritize by real exploitability, not CVSS score

  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers

  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries

  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure

What We're Looking For

  • You've found and fixed real vulnerabilities in production applications - not just run scanners

  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws

  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass

  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)

  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them

  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation

  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Bonus Points

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)

  • Offensive security skills - you've done penetration testing and can think like an attacker

  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense

  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)

  • You've built custom security tooling that a team still uses

  • Contributions to open source security projects or published vulnerability research

Why Mercor

  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.

  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.

  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.

  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.

    Benefits

    • Bi-annual performance bonus structure

    • Generous equity grant vested over 4 years

    • Up to $15k Relocation bonus

    • $10K housing bonus (if you live within 0.5 miles of our office)

    • $1.5K monthly stipend for meals

    • Free Equinox membership

    • $200 monthly laundry reimbursement

    • $200 monthly personal wellness reimbursement

    • Health, Dental, Vision insurance

Bereit, sich bei Mercor zu bewerben?
Bei Mercor bewerben

Wie sich dieses Gehalt für Security Engineer vergleicht

Diese Stelle zahlt $265,000/yrim Einklang mit der üblichen Spanne für Security Engineer Stellen.

$172,500 dem Median $235,000 $355,500

Übliche Spanne $199,671–$275,000/yr, aus 225 vergleichbaren Security Engineer Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Security Engineer ansehen →

Ähnliche Jobs

Mercor
Security Engineer, Cloud Infrastructure
Mercor
⚡ Früh bewerben San Francisco or NYC Vor Ort $130,000–$400,000
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
Juicebox
Security Engineer
Juicebox
⚡ Früh bewerben San Francisco Vor Ort $160,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
OpenAI
Software Engineer, HSM Infrastructure Security, Consumer Devices
OpenAI
⚡ Früh bewerben San Francisco Vor Ort $347,000–$445,000
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
WRITER
Security engineer, detection and response
WRITER
⚡ Früh bewerben San Francisco, CA Hybrid $131,800–$257,700
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
WRITER
Security engineer, application security
WRITER
⚡ Früh bewerben New York City, NY Hybrid $131,800–$257,700
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
Pinterest
Sr. Security Software Engineer, Security Operations
Pinterest
⚡ Früh bewerben San Francisco, CA, US; Remote,... · standortgebunden $155,584–$320,320
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
Pinterest
Security Software Engineer II, Detection and Response
Pinterest
⚡ Früh bewerben San Francisco, CA, US; Remote,... · standortgebunden $123,696–$254,667
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
Pinterest
Sr. Security Software Engineer, Application Security
Pinterest
⚡ Früh bewerben Chicago, IL, US; Remote, US · standortgebunden $155,584–$320,320
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
Cloudflare
Staff/Principal Software Engineer - Security Platform
Cloudflare
⚡ Früh bewerben Distributed Vor Ort $220,000–$303,000
● Neu 👁 Gesehen ✓ Beworben vor 15 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Mercor

Alle Jobs bei Mercor ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos