Security Engineer, Cloud Infrastructure
San Francisco or NYC • FullTime
Posted 5mo ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
AI Infrastructure Engineer
About the job
Mercor is seeking a Security Engineer to own cloud and infrastructure security at a company where tenant isolation is a critical enterprise requirement. You will architect multi-account AWS isolation, harden Kubernetes clusters, deploy cloud security posture management, and build the infrastructure that lets Mercor serve enterprise clients who demand the highest security bar. This role involves using AI heavily in security work, including building alongside AI code-gen tools, using LLMs to accelerate infrastructure review and policy authoring, and automating repetitive tasks. If you prefer writing Terraform modules over filling out spreadsheets, you will fit in here.
Responsibilities
- Architect multi-account AWS tenant isolation strategies, including dedicated accounts, SCPs, network boundaries, and data segregation.
- Implement and manage cloud security posture management using Wiz CSPM for continuous monitoring, misconfiguration detection, and automated remediation.
- Harden Kubernetes clusters, focusing on pod security standards, network policies, secrets management, and runtime protection.
- Develop and enforce infrastructure-as-code security guardrails using Terraform/CloudFormation policies.
- Design and implement IAM architecture with least-privilege access controls across AWS, Snowflake, and internal services.
- Build incident response infrastructure, including logging pipelines, forensic readiness, and blast radius containment.
Requirements
- Deep AWS security expertise, including architecting multi-account strategies, writing SCPs, and hardening production environments.
- Proven experience with Kubernetes security in production environments.
- Strong infrastructure-as-code skills (Terraform, CloudFormation, or Pulumi).
- Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar).
- Understanding of cloud-level network security (VPCs, security groups, transit gateways, PrivateLink).
- Experience designing tenant isolation for multi-tenant SaaS, including data segregation, compute isolation, and network boundaries.
- 5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance