Security Engineer

Mercor, Inc.
San Francisco, CA, United States
5 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Training Data Application Programming Interfaces (APIs) Artificial Intelligence Business Logic Software System Penetration Testing JIRA User Authentication Bug Tracking Systems Software Bug Management Code Review Cyber Security Continuous Delivery
+17 more
Continuous Integration Python (Programming Language) Machine Learning Open Source Technology Systems Development Life Cycle Secure Coding Software Engineering TypeScript Software Vulnerability Management Web Application Frameworks Software Security Firewalls (Computer Science) Multiplatform Data Pipelines Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
  • Vulnerability management processes that prioritize by real exploitability, not CVSS score
  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure, * AI-native AppSec. You’ll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
  • Ownership from day one. You’ll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
  • See the future early. Working alongside AI labs means you’ll understand frontier model capabilities months before the market.

Requirements

  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Bonus Points

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills - you’ve done penetration testing and can think like an attacker
  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
  • You’ve built custom security tooling that a team still uses
  • Contributions to open source security projects or published vulnerability research, Analysis Skills, Application Programming Interface (API), Applications Security, Artificial Intelligence (AI), Atlassian JIRA, Authentication, Benchmarking, Bug Tracking/Defect Management, Building Codes, Category Development, Code Reviews, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Dental Insurance, Embedded Systems, Establish Priorities, Firewalls, Fortune 500 Customers, Human Intelligence (HUMINT), Injections, Machine Tool, Multiplatform/Cross-Platform, Open Source, Product Lifecycle, Public/Media/Press/Analyst Relations, Sales Pipeline, Sockets, Software Development Lifecycle (SDLC), Supply Chain, Threat Modeling, Training/Teaching, Vision Plan, Web Application Framework

Benefits & conditions

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of our office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

About the company

Mercor’s mission is to organize human intelligence to power the AI economy. We’re a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor’s APEX benchmark family measures AI’s real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.

You’ll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You’ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you’d rather write a CodeQL query than file a Jira ticket, you’ll fit in here.

We’re in-person five days a week at our SF headquarters, with first Fridays remote.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:00 min

Misconceptions about TypeScript safety capabilities

Simone Sanfratello · JS Congress

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

Videos

See all

Related articles

See all