CybersecurityJobs.io
← Back to all jobs

Job Description

Mercor is building a platform where the application layer is treated as the most important security surface. In this role, you will own application security end-to-end for a fast-moving product used by 300K+ experts and enterprise clients that handle sensitive AI training data.

You will embed security into the SDLC, improve how vulnerabilities are found and remediated, and help operationalize secure development across engineering. The position is based in New York, NY (onsite), with a salary range of USD 130,000 - 400,000 per yearly and a minimum of 5 years of relevant experience.

Responsibilities

  • Run security review workflows integrated into the SDLC, including PR-level analysis to catch authentication bugs, injection flaws, and business logic errors before release.
  • Own SAST/DAST pipelines integrated into CI/CD so security shifts earlier in the process without slowing deployments.
  • Operate vulnerability management using prioritization based on real exploitability, not CVSS score alone.
  • Define secure coding standards and guardrails that make the safe path easier for 50+ engineers to follow.
  • Create threat models for new features and architectural changes, with particular focus on AI data pipelines, payment flows, and multi-tenant boundaries.
  • Support bug bounty program operations by triaging HackerOne reports, validating findings, and driving fixes through to closure.

Requirements

  • Have identified and fixed real vulnerabilities in production applications, not only scan results.
  • Demonstrate strong web application security depth, with OWASP Top 10 as a baseline and the ability to reason about attack chains and business logic flaws.
  • Strong ability in at least one language: Python, TypeScript, or Go, including reviewing PRs and spotting issues such as an auth bypass.
  • Experience building or tuning SAST/DAST tooling, including familiarity with tools such as Semgrep, CodeQL, Snyk, and Burp (or similar).
  • Comfort threat modeling modern web frameworks, APIs, and authentication patterns.
  • Experience managing a vulnerability pipeline from discovery and prioritization through verified remediation.
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus.

Technologies

  • Python, TypeScript, Go
  • Semgrep, CodeQL, Snyk, Burp
  • HackerOne
  • OWASP Top 10

Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of the office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

Bonus Points

  • Experience running or triaging a bug bounty program such as HackerOne or Bugcrowd.
  • Offensive security skills including penetration testing and attacker-minded analysis.
  • Experience securing AI/ML applications, including model serving APIs, training data pipelines, and prompt injection defense.
  • Familiarity with supply chain security such as dependency scanning and registry firewalls (Socket, Snyk).
  • Built custom security tooling that other teams still use.
  • Contributions to open source security projects or published vulnerability research.

Why Mercor

  • Real problem: application security at scale is hard, and the role focuses on defenses that matter across a fast-moving platform.
  • AI-native AppSec: use frontier AI tools daily for code review, vulnerability analysis, and work that benefits from an AI co-pilot.
  • Ownership from day one: you own application security across code review processes, CI/CD security, and bug bounty operations.
  • See the future early: work alongside AI labs to understand frontier model capabilities months before broader market adoption.

Similar Jobs