Mercor

Security Engineer, Application Security

Mercor
Apply
4 months ago
San Francisco, CA, USA or New York, NY, USASenior
H1B Sponsor

Base Salary

$130k - $500k/yr

Responsibilities

  • Embed security review workflows into the software development lifecycle, including pull-request analysis for authentication bugs, injection flaws, and business logic errors.
  • Build SAST/DAST pipelines integrated into CI/CD.
  • Create vulnerability management processes that prioritize real exploitability and drive remediation to closure.
  • Develop secure coding standards and guardrails for more than 50 engineers.
  • Threat-model new features and architecture changes, especially AI data pipelines, payment flows, and multi-tenant boundaries.
  • Operate the bug bounty program by triaging HackerOne reports, validating findings, and coordinating fixes.
  • Use AI code-generation tools and LLMs to accelerate code review, threat modeling, and repetitive AppSec work.

Requirements

  • At least 5 years of professional experience in application security, security engineering, or software engineering with a strong security focus.
  • Production experience finding and fixing real application vulnerabilities rather than only running scanners.
  • Deep understanding of web application security, including OWASP Top 10, attack chains, and business logic flaws.
  • Strong proficiency in at least one of Python, TypeScript, or Go.
  • Experience building or tuning SAST/DAST tooling such as Semgrep, CodeQL, Snyk, or Burp.
  • Understanding of modern web frameworks, APIs, and authentication patterns sufficient to threat model applications.
  • Experience managing vulnerabilities from discovery through prioritization and verified remediation.
  • Bug bounty operations, offensive security, penetration testing, AI/ML application security, supply chain security, custom security tooling, open-source security contributions, or vulnerability research are preferred.

Benefits

  • In-person five days per week at the San Francisco, New York City, or London office, with first Fridays remote.
  • Opportunity to own application security across a fast-moving platform serving more than 300,000 experts and enterprise clients.
  • Daily use of frontier AI tools for code review, vulnerability analysis, and security automation.

Categories

Mercor

About Mercor

201-500 employees

We find the best experts in every professional domain and put their knowledge to work training frontier models. Through APEX, we measure whether those models can actually perform economically valuable work. We're also bringing that expertise to enterprises: deploying custom AI agents, staffing teams with vetted domain experts, and helping organizations encode their own knowledge into AI systems.