- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- 5 months ago
About this role
About Mercor
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
What You'll Build:
Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
Vulnerability management processes that prioritize by real exploitability, not CVSS score
Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
What We're Looking For
You've found and fixed real vulnerabilities in production applications - not just run scanners
Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Bonus Points
Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
Offensive security skills - you've done penetration testing and can think like an attacker
Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
You've built custom security tooling that a team still uses
Contributions to open source security projects or published vulnerability research
Why Mercor
The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
Bi-annual performance bonus structure
Generous equity grant vested over 4 years
Up to $15k Relocation bonus
$10K housing bonus (if you live within 0.5 miles of our office)
$1.5K monthly stipend for meals
Free Equinox membership
$200 monthly laundry reimbursement
$200 monthly personal wellness reimbursement
Health, Dental, Vision insurance
As published by Mercor. Applications are handled on their site.
Skills this posting mentions
About Mercor
Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day.
All 87 openings at MercorOne click, then it is written
Apply to Mercor with a resume written for this role.
Queue Security Engineer, Application Security and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Mercor’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Mercor
See all- 5 weeks ago
- 5 weeks ago
- 5 weeks ago
Product Operations Manager, Talent Experience
San Francisco, California
$140k - $210k/yrManagerProduct - 5 weeks ago
- 5 weeks ago
- 5 weeks ago
Similar roles elsewhere
See more- Today
Senior Frontend Engineer, Ads Creative
RedditRemote - United StatesRemote
$191k - $267k/yrSeniorEngineering - Today
- Today
Senior Software Engineer, Agentic Ads Experience
RedditRemote - United StatesRemote
$217k - $304k/yrSeniorEngineering - Today
Staff Technical Product Manager, Ads ML Platform
RedditRemote - United StatesRemote
$217k - $304k/yrStaffEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Mercor publishes. Refolk is not the employer and does not handle their hiring. Applications go to Mercor directly.