Security Engineer, Application Security

San Francisco FullTime

Posted 9d ago

Job Location

San Francisco

Tech Stack

Remote Work Policy

On-site

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Mercor is a leading AI data company building the layer between human expertise and frontier models. We are seeking a Security Engineer, Application Security to own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You will embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away repetitive work.

Responsibilities

  • Embed in the development lifecycle to review code for exploitable flaws.
  • Build security tooling into CI/CD pipelines.
  • Drive vulnerability remediation across the platform.
  • Develop security review workflows embedded in the SDLC for PR-level analysis.
  • Integrate SAST/DAST pipelines into CI/CD.
  • Establish vulnerability management processes that prioritize by real exploitability.
  • Define secure coding standards and guardrails for engineers.
  • Create threat models for new features and architecture changes, especially concerning AI data pipelines, payment flows, and multi-tenant boundaries.
  • Operate the bug bounty program, including triaging reports, validating findings, and driving fixes.

Requirements

  • Proven experience finding and fixing real vulnerabilities in production applications.
  • Deep understanding of web application security, including OWASP Top 10, attack chains, and business logic flaws.
  • Proficiency in at least one of Python, TypeScript, or Go.
  • Experience building or tuning SAST/DAST tooling (e.g., Semgrep, CodeQL, Snyk, Burp).
  • Understanding of modern web frameworks, APIs, and authentication patterns for threat modeling.
  • Experience managing a vulnerability pipeline from discovery to remediation.
  • 5+ years of professional experience in application security, security engineering, or software engineering with a security focus.

Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus (if living within 0.5 miles of office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

About Mercor

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.