AI-Driven AppSec Engineer — Ownership, Equity, Relocation

Fairweather, LLC

New York (NY)

On-site

USD 140,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Relocation bonus
Housing stipend
Meal stipend
Equinox membership
Laundry reimbursement
Wellness reimbursement
Health insurance
Dental insurance
Vision insurance

Job summary

Mercor is seeking a Security Engineer to own application security across the development lifecycle. You will review code for exploitable flaws, embed security tooling into CI/CD, and drive remediation for a platform serving 300K+ experts and enterprise clients handling sensitive AI training data.

You’ll work in-person five days a week in our NYC or SF offices, collaborating with researchers, operators, and AI companies at the forefront of AI security.

Qualifications

  • You've found and fixed real vulnerabilities in production applications - not just run scanners.
  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws.
  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass.
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar).
  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them.
  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation.
  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus.

Responsibilities

  • Embed security review workflows in the SDLC with PR-level analysis.
  • Develop and integrate SAST/DAST pipelines into CI/CD.
  • Drive vulnerability remediation prioritization and closure.
  • Create threat models for new features and architectures, especially AI data pipelines and multi-tenant boundaries.
  • Operate a bug bounty program workflow, triaging reports and guiding fixes.

Skills

Web app security
Python/TypeScript/Go
SAST/DAST tooling
CI/CD security
Threat modeling
Vulnerability remediation

Tools

Semgrep
CodeQL
Snyk
Burp Suite

Job description

Mercor is seeking a Security Engineer to own application security across the development lifecycle. You will review code for exploitable flaws, embed security tooling into CI/CD, and drive remediation for a platform serving 300K+ experts and enterprise clients handling sensitive AI training data.

You’ll work in-person five days a week in our NYC or SF offices, collaborating with researchers, operators, and AI companies at the forefront of AI security.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Application Security at Mercor Alabaster New York, NY
Security Engineer, Application Security at Mercor Alabaster New York, NY

Fairweather, LLC • New York (NY)

On-site
USD 140,000 - 200,000
Relocation bonus
Housing stipend
Meal stipend
+6
Security Engineer, Application Security
Security Engineer, Application Security

Mercor • New York (NY), San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior AI-Driven AppSec Engineer
Senior AI-Driven AppSec Engineer

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000
AI-Driven AppSec Lead with Equity & Unlimited PTO
AI-Driven AppSec Lead with Equity & Unlimited PTO

Zeta Global • San Francisco (CA)

On-site
USD 140,000 - 180,000
Unlimited PTO
Excellent medical, dental, and vision
Employee Equity
+1
Proactive Security Engineer for AI DevTool - Equity
Proactive Security Engineer for AI DevTool - Equity

Rise Technical Recruitment Limited • San Francisco (CA)

On-site
USD 200,000 - 230,000
Equity
Benefits
401(k)
Senior AppSec Engineer — AI-Driven SaaS Security Leader
Senior AppSec Engineer — AI-Driven SaaS Security Leader

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
AI Security Researcher & Offensive Security Trainer
AI Security Researcher & Offensive Security Trainer

Mercor • Antioch (CA)

Remote
USD 120,000 - 180,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Security Engineer - AI Platform, Threat Modeling & Equity
Security Engineer - AI Platform, Threat Modeling & Equity

Nooks • United States

Remote
USD 200,000 - 315,000
Equity options
Generous perks
Comprehensive benefits
AI-Driven AppSec Engineer
AI-Driven AppSec Engineer

Collective Hub Inc. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid Work Model
Fresh Lunch Provided on in-office days
Commuter Support: $150 monthly
+6