Middle · Удалённо · San Francisco or NYC · Английский B2
Навыки
Burp Suite
CI/CD
Code review
Jira
Machine Learning
OWASP
Ответственность за результат
Ещё 6
Пентест
Python
SAST / DAST
Жизненный цикл разработки
TypeScript
Управление уязвимостями
О компании и продукте
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.
Задачи
Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
Vulnerability management processes that prioritize by real exploitability, not CVSS score
Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
Требования
You've found and fixed real vulnerabilities in production applications - not just run scanners
Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Будет плюсом
Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
Offensive security skills - you've done penetration testing and can think like an attacker
Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense