> Markdown version of [/jobs/ext/2769656-security-engineer](https://www.wearedevelopers.com/jobs/ext/2769656-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Mercor, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Application Programming Interfaces (APIs), Artificial Intelligence, Business Logic, Software System Penetration Testing, JIRA, User Authentication, Bug Tracking Systems, Software Bug Management, Code Review, Cyber Security, Continuous Delivery, Continuous Integration, Python (Programming Language), Machine Learning, Open Source Technology, Systems Development Life Cycle, Secure Coding, Software Engineering, TypeScript, Software Vulnerability Management, Web Application Frameworks, Software Security, Firewalls (Computer Science), Multiplatform, Data Pipelines, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 7, 2026 - **Apply:** https://www.careerbuilder.com/job-details/security-engineer-application-security-san-francisco-ca--e8f517c0-ff71-45ad-a8f2-d26cb53e3232 ## About the Role * Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass * Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) * You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them * Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation * 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus Bonus Points * Experience running or triaging a bug bounty program (HackerOne, Bugcrowd) * Offensive security skills - you've done penetration testing and can think like an attacker * Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense * Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk) * You've built custom security tooling that a team still uses * Contributions to open source security projects or published vulnerability research, Analysis Skills, Application Programming Interface (API), Applications Security, Artificial Intelligence (AI), Atlassian JIRA, Authentication, Benchmarking, Bug Tracking/Defect Management, Building Codes, Category Development, Code Reviews, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Dental Insurance, Embedded Systems, Establish Priorities, Firewalls, Fortune 500 Customers, Human Intelligence (HUMINT), Injections, Machine Tool, Multiplatform/Cross-Platform, Open Source, Product Lifecycle, Public/Media/Press/Analyst Relations, Sales Pipeline, Sockets, Software Development Lifecycle (SDLC), Supply Chain, Threat Modeling, Training/Teaching, Vision Plan, Web Application Framework ## Description * Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship * SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys * Vulnerability management processes that prioritize by real exploitability, not CVSS score * Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers * Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries * Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure, * AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot. * Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations. * See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119)