- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- 5 months ago
About this role
About Mercor
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own cloud and infrastructure security at a company where tenant isolation is a critical enterprise requirement. Mercor's customers - including frontier AI labs - need hard guarantees that their data stays within strict boundaries. This is not a compliance checkbox role. You'll architect multi-account AWS isolation, harden Kubernetes clusters, deploy cloud security posture management, and build the infrastructure that lets Mercor serve enterprise clients who demand the highest security bar.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate infrastructure review and policy authoring, and automating away the repetitive work that slows infrastructure security down. If you'd rather write a Terraform module than fill out a spreadsheet, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
What You'll Build:
Multi-account AWS tenant isolation architecture - dedicated accounts, SCPs, network boundaries, and data segregation for enterprise clients
Cloud security posture management using Wiz CSPM - continuous monitoring, misconfiguration detection, and automated remediation
Kubernetes security hardening - pod security standards, network policies, secrets management, and runtime protection
Infrastructure-as-code security guardrails - Terraform/CloudFormation policies that prevent insecure deployments before they reach production
IAM architecture and least-privilege access controls across AWS, Snowflake, and internal services
Incident response infrastructure - logging pipelines, forensic readiness, and blast radius containment
What We're Looking For
Deep AWS security expertise - you've architected multi-account strategies, written SCPs, and hardened production environments
Experience with Kubernetes security in production - not just tutorials, you've secured real clusters running real workloads
Strong infrastructure-as-code skills - Terraform, CloudFormation, or Pulumi - you think in code, not console clicks
Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar) - deploying, tuning, and driving remediation
Understanding of network security at the cloud level - VPCs, security groups, transit gateways, PrivateLink
You've designed tenant isolation for multi-tenant SaaS - data segregation, compute isolation, network boundaries
5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus
Bonus Points
Experience with Snowflake security - schema-level isolation, access controls, data sharing governance
Familiarity with container runtime security (Falco, SentinelOne Cloud Workload Protection, or similar)
Offensive cloud security skills - you've exploited misconfigurations and understand the attacker's perspective
Experience building compliance-ready infrastructure (SOC 2, ISO 27001, FedRAMP)
You've handled cloud security incidents - forensics, containment, and root cause analysis in AWS
Contributions to open source infrastructure security tools
Why Mercor
The deliverable is concrete. Enterprise clients require tenant isolation as a baseline. You'll build infrastructure that directly enables the business.
AI-native infrastructure security. You'll use frontier AI tools daily - for policy authoring, misconfiguration analysis, and anything that benefits from an AI co-pilot.
Ownership from day one. You'll own the entire cloud security domain - from AWS architecture to Kubernetes hardening to CSPM operations.
See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
Bi-annual performance bonus structure
Generous equity grant vested over 4 years
Up to $15k Relocation bonus
$10K housing bonus (if you live within 0.5 miles of our office)
$1.5K monthly stipend for meals
Free Equinox membership
$200 monthly laundry reimbursement
$200 monthly personal wellness reimbursement
Health, Dental, Vision insurance
As published by Mercor. Applications are handled on their site.
Skills this posting mentions
About Mercor
Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day.
All 87 openings at MercorOne click, then it is written
Apply to Mercor with a resume written for this role.
Queue Security Engineer, Cloud Infrastructure and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Mercor’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Mercor
See all- 5 weeks ago
- 5 weeks ago
- 5 weeks ago
Product Operations Manager, Talent Experience
San Francisco, California
$140k - $210k/yrManagerProduct - 5 weeks ago
- 5 weeks ago
- 5 weeks ago
Similar roles elsewhere
See more- Today
Senior Frontend Engineer, Ads Creative
RedditRemote - United StatesRemote
$191k - $267k/yrSeniorEngineering - Today
- Today
Senior Software Engineer, Agentic Ads Experience
RedditRemote - United StatesRemote
$217k - $304k/yrSeniorEngineering - Today
Staff Technical Product Manager, Ads ML Platform
RedditRemote - United StatesRemote
$217k - $304k/yrStaffEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Mercor publishes. Refolk is not the employer and does not handle their hiring. Applications go to Mercor directly.