Jobs Companies Mercor Security Engineer, Application Security

Sobre este puesto de Security Engineer, Application Security en Mercor

Mercor · Presencial · San Francisco or NYC

About Mercor

Mercor's mission is to organize human intelligence to power the AI economy. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $3 million a day.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.

You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.

We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build:

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship

  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys

  • Vulnerability management processes that prioritize by real exploitability, not CVSS score

  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers

  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries

  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure

What We're Looking For

  • You've found and fixed real vulnerabilities in production applications - not just run scanners

  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws

  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass

  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)

  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them

  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation

  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Bonus Points

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)

  • Offensive security skills - you've done penetration testing and can think like an attacker

  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense

  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)

  • You've built custom security tooling that a team still uses

  • Contributions to open source security projects or published vulnerability research

Why Mercor

  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.

  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.

  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.

  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.

    Benefits

    • Bi-annual performance bonus structure

    • Generous equity grant vested over 4 years

    • Up to $15k Relocation bonus

    • $10K housing bonus (if you live within 0.5 miles of our office)

    • $1.5K monthly stipend for meals

    • Free Equinox membership

    • $200 monthly laundry reimbursement

    • $200 monthly personal wellness reimbursement

    • Health, Dental, Vision insurance

¿Listo para postularte en Mercor?
Postúlate en Mercor

Cómo se compara este salario de Security Engineer

Este puesto paga $265,000/yrpor encima de el rango típico para los puestos de Security Engineer.

$175,000 la mediana de $232,500 $339,000

Rango típico $197,500–$265,000/yr, a partir de 224 ofertas comparables de Security Engineer en JobsRadar (salario anualizado en USD). Ver datos salariales de Security Engineer →

Empleos similares

Higgsfield
Security Infrastructure Engineer
Higgsfield
⚡ Postúlate pronto Almaty, Kazakhstan Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 33m
Fluidstack
Information Security Engineer, Bare Metal
Fluidstack
⚡ Postúlate pronto New York, NY Presencial $269,000–$330,000
● Nuevo 👁 Visto ✓ Postulado hace 34m
Fluidstack
Security Engineer, Infrastructure
Fluidstack
⚡ Postúlate pronto New York, NY Presencial $218,000–$252,000
● Nuevo 👁 Visto ✓ Postulado hace 35m
Savvy Wealth
Senior Application Security Engineer
Savvy Wealth
⚡ Postúlate pronto NYC Office Híbrido $220,000–$235,000
● Nuevo 👁 Visto ✓ Postulado hace 2h
Braze
Senior Security Engineer, Enterprise Security
Braze
⚡ Postúlate pronto San Francisco Presencial $128,900–$180,000
● Nuevo 👁 Visto ✓ Postulado hace 3h
MongoDB
Site Reliability Engineer (Senior or Staff), Infrastructure Security
MongoDB
⚡ Postúlate pronto Austin; New York City; San Fra... Presencial $127,000–$249,000
● Nuevo 👁 Visto ✓ Postulado hace 6h
MongoDB
Security Software Engineer, Infrastructure Security (Staff or Senior)
MongoDB
⚡ Postúlate pronto Austin; New York City; San Fra... Presencial $127,000–$249,000
● Nuevo 👁 Visto ✓ Postulado hace 6h
AN
Lead Security & IT Engineer
Anodize
⚡ Postúlate pronto San Francisco or Los Altos, CA Presencial
● Nuevo 👁 Visto ✓ Postulado hace 16h
StackAI
Product Security Engineer
StackAI
⚡ Postúlate pronto SF Office Híbrido $210,000–$240,000
● Nuevo 👁 Visto ✓ Postulado hace 16h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Mercor

Ver todos los empleos en Mercor →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis