Mercor

Security Engineer, Application Security

Middle · Удалённо · San Francisco or NYC · Английский B2

Навыки

  • Burp Suite
  • CI/CD
  • Code review
  • Jira
  • Machine Learning
  • OWASP
  • Ответственность за результат
Ещё 6
  • Пентест
  • Python
  • SAST / DAST
  • Жизненный цикл разработки
  • TypeScript
  • Управление уязвимостями

О компании и продукте

  • Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
  • Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
  • You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

Задачи

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
  • Vulnerability management processes that prioritize by real exploitability, not CVSS score
  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure

Требования

  • You've found and fixed real vulnerabilities in production applications - not just run scanners
  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Будет плюсом

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills - you've done penetration testing and can think like an attacker
  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
  • You've built custom security tooling that a team still uses
  • Contributions to open source security projects or published vulnerability research
  • WHY MERCOR
  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform
  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot
  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations
  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market

Условия

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of our office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

Паспорт вакансии

История публикации

Появилась в Вакандии27 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели сегодня
Среди похожихНет данных26 из 30 · похожих вакансий слишком мало для сравнения

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдMiddleвыведено из другого признака
Формат работыУдалённовычитано из текста вакансии
ГеографияSan Francisco or NYC
Зарплата≈ 16 667 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки753 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • ashbyОсновная публикация · 2026-04-15

Работодатель

Mercor

37 активных вакансий · вилка работодателя указана в 5%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеjobs.ashbyhq.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же грейд

    GRS Recruitment

    Cybersecurity Engineer

    • Middle
    • Удалённо
    • Никосия, Кипр
    Подробнее