Application Security Specialist - Fully Remote
Mercor, Inc.
New York, NY, United States
6 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.careerjet.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$145,600.0 - $187,200.0
Working hours
Regular working hours
Job source
Tech stack
Training Data
Artificial Intelligence
Software System Penetration Testing
Continuous Integration
Machine Learning
Secure Coding
SQL Injection
Software Security
GWAPT
Devsecops
Docker
Static Application Security Testing
+2 more
Vulnerability Analysis
Dynamic Application Security Testing
Job description
- Evaluate the quality, fidelity, and completeness of vulnerability-reproduction and remediation tasks for AI model training.
- Assess CVE reproductions for faithfulness and ensure fixes are sound.
- Verify rigorous logic and ensure Docker-based lab environments accurately recreate exploitable conditions.
- Provide clear, rubric-based written feedback to improve model outputs.
- Collaborate with AI research teams to enhance training data quality and downstream performance.
- Work independently and asynchronously to meet deadlines while improving AI model performance., PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity., Customer Service Specialists work closely with wholesale and retail customers to determine their needs, answer their questions about Sherwin-Williams products, and recommend the ri…
- 7 days ago
Requirements
Must-Have
- 3+ years of hands-on experience in application security, penetration testing, or vulnerability research.
- Strong understanding of CVE vulnerability taxonomy and severity frameworks (CVSS, CWE, CAPEC).
- Demonstrated expertise in secure coding and remediation across common vulnerability classes (SQL injection, command injection, buffer overflow, deserialization, SSRF, misconfigurations, privilege escalation).
- Experience designing or evaluating two-part verification logic (functionality tests + vulnerability tests).
- Proficiency with Docker and Docker Compose for multi-container vulnerability reproduction environments.
Preferred
- OSCP, GPEN, GWAPT, or equivalent offensive-security certification.
- Experience with CVE disclosure, responsible vulnerability reporting, or maintaining exploit proof-of-concept code.
- Background in DevSecOps, CI/CD security gating, or SAST/DAST tooling.
- Prior technical content review, assessment design, or QA for security-focused engineering tasks.
About the company
Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D’Angelo, Larry Summers, and Jack Dorsey.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerjet.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago