Security Engineer, Application Security

Mercor

New York, San Francisco (NY, CA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading AI development company in New York seeks an experienced Application Security Engineer. You will own the application security domain, embedding security in the development lifecycle, integrating tools into CI/CD, and managing vulnerabilities. The ideal candidate has over 5 years of experience in application security, a deep understanding of web security, and the ability to build and tune security tooling. Embrace AI tools daily while contributing to high-visibility solutions within a dynamic team environment.

Qualifications

  • 5+ years of professional experience in application security or related field.
  • Found and fixed real vulnerabilities in production applications.
  • Strong understanding of web application security and OWASP Top 10.

Responsibilities

  • Embed security review workflows in the SDLC.
  • Integrate SAST/DAST pipelines into CI/CD processes.
  • Manage the vulnerability pipeline from discovery to remediation.

Skills

Web application security
Python
TypeScript
Go
SAST/DAST tooling
Threat modeling
Vulnerability management

Tools

Semgrep
CodeQL
Snyk
Burp

Job description

About Mercor

Mercor is defining the future of work. We partner with leading AI labs and enterprises to provide the human intelligence essential to A I development.

Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast‑paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society.

Mercor is a profitable Series C company valued at $10 billion. We work in‑person five days a week in our San Francisco, NYC, or London offices.

You’ll own application security at a company where the app layer is the highest‑priority security surface. This is not a scan‑and‑triage role. You’ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code‑gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you’ll fit in here.

We're in‑person five days a week at our SF headquarters, with first Fridays remote.

What You’ll Build:
  • Security review workflows embedded in the SDLC – PR‑level analysis that catches auth bugs, injection flaws, and business logic errors before they ship

  • SAST/DAST pipelines integrated into CI/CD – shifting security left without slowing down deploys

  • Vulnerability management processes that prioritize by real exploitability, not CVSS score

  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers

  • Threat models for new features and architecture changes – especially around AI data pipelines, payment flows, and multi‑tenant boundaries

  • Bug bounty program operations – triaging HackerOne reports, validating findings, and driving fixes to closure

What We’re Looking For
  • You've found and fixed real vulnerabilities in production applications – not just run scanners

  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws

  • Strong in at least one of Python, TypeScript, or Go – you can read a PR and spot the auth bypass

  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)

  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them

  • Experience managing a vulnerability pipeline – from discovery through prioritization to verified remediation

  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Bonus Points
  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)

  • Offensive security skills – you've done penetration testing and can think like an attacker

  • Experience securing AI/ML applications – model serving APIs, training data pipelines, prompt injection defense

  • Familiarity with supply chain security – dependency scanning, registry firewalls (Socket, Snyk)

  • You've built custom security tooling that a team still uses

  • Contributions to open source security projects or published vulnerability research

Why Mercor
  • The problem is real. Application security at scale is hard – you'll build defenses that matter across a fast‑moving platform.

  • AI‑native AppSec – you'll use frontier AI tools daily – for code review, vulnerability analysis, and anything that benefits from an AI co‑pilot.

  • Ownership from day one. You'll own the entire application security domain – from code review processes to CI/CD security to bug bounty operations.

  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Application Security at Mercor Alabaster New York, NY
Security Engineer, Application Security at Mercor Alabaster New York, NY

Fairweather, LLC • New York (NY)

On-site
USD 140,000 - 200,000
Relocation bonus
Housing stipend
Meal stipend
+6
Security Engineer, Cloud Infrastructure
Security Engineer, Cloud Infrastructure

Mercor • New York (NY), San Francisco (CA)

On-site
USD 120,000 - 160,000
Equity ownership
Relocation support
Housing support
+3
Software Engineer, Enterprise Applied AI
Software Engineer, Enterprise Applied AI

Mercor • San Francisco (CA)

On-site
USD 180,000 - 260,000
Performance bonus
Equity grant
Relocation bonus
+6
Software Engineer, Identity
Software Engineer, Identity

Mercor, Inc. • San Francisco (CA)

On-site
USD 120,000 - 150,000
Generous equity, vested over 4 years
Up to $15K relocation bonus
$10K housing bonus
+5
Software Engineer, Applied AI
Software Engineer, Applied AI

Mercor • San Francisco (CA)

On-site
USD 130,000 - 500,000
Bi-annual performance bonus
Generous equity grants
Relocation bonus up to $15k
+6
Software Engineer, Platform
Software Engineer, Platform

Mercor • San Francisco (CA), New York (NY)

On-site
USD 120,000 - 160,000
Bi-annual performance bonus structure
Generous equity grant vested over 4 years
Up to $15k Relocation bonus
+6
Product Manager, Trust & Safety
Product Manager, Trust & Safety

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 210,000
Bi-annual bonus
Equity grant
Relocation bonus
+6
Product Manager, Trust & Safety
Product Manager, Trust & Safety

Mercor • San Francisco (CA)

On-site
USD 170,000 - 260,000
Bi-annual bonus
Equity grant
Relocation assistance
+6
Software Engineer, Fraud
Software Engineer, Fraud

Mercor • New York (NY), San Francisco (CA)

On-site
USD 100,000 - 130,000
Bi-annual performance bonus
Generous equity grant
Relocation bonus up to $15k
+6
Engineering Manager, Fraud & Compliance
Engineering Manager, Fraud & Compliance

Mercor • San Francisco (CA)

On-site
USD 150,000 - 200,000
Generous equity, vested over 4 years
Up to $15K relocation bonus
$10K housing bonus
+5