Security Engineer, Application Security
San Francisco • FullTime
Posted 9d ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Mercor is a leading AI data company building the layer between human expertise and frontier models. We are seeking a Security Engineer, Application Security to own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You will embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away repetitive work.
Responsibilities
- Embed in the development lifecycle to review code for exploitable flaws.
- Build security tooling into CI/CD pipelines.
- Drive vulnerability remediation across the platform.
- Develop security review workflows embedded in the SDLC for PR-level analysis.
- Integrate SAST/DAST pipelines into CI/CD.
- Establish vulnerability management processes that prioritize by real exploitability.
- Define secure coding standards and guardrails for engineers.
- Create threat models for new features and architecture changes, especially concerning AI data pipelines, payment flows, and multi-tenant boundaries.
- Operate the bug bounty program, including triaging reports, validating findings, and driving fixes.
Requirements
- Proven experience finding and fixing real vulnerabilities in production applications.
- Deep understanding of web application security, including OWASP Top 10, attack chains, and business logic flaws.
- Proficiency in at least one of Python, TypeScript, or Go.
- Experience building or tuning SAST/DAST tooling (e.g., Semgrep, CodeQL, Snyk, Burp).
- Understanding of modern web frameworks, APIs, and authentication patterns for threat modeling.
- Experience managing a vulnerability pipeline from discovery to remediation.
- 5+ years of professional experience in application security, security engineering, or software engineering with a security focus.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if living within 0.5 miles of office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance