Mercor
Security Engineer, Application Security
About this role
Mercor is seeking an Application Security Engineer to lead security initiatives at the application layer, working closely with development teams to enhance secure coding practices and embed security throughout the software development lifecycle. The role involves hands-on vulnerability management, code reviews, and building security tools that leverage AI technologies within a fast-paced environment.
What you'll do
- Embed security review workflows in the development lifecycle
- Integrate SAST/DAST pipelines into CI/CD processes
- Manage vulnerability prioritization based on exploitability
- Establish secure coding standards for engineers
- Create threat models for new features and architectures
- Oversee the operations of the bug bounty program
What they're looking for
- Experienced in identifying vulnerabilities in production
- Proficient with web application security principles
- Strong coding skills in Python, TypeScript, or Go
- Knowledgeable in SAST/DAST tools like Semgrep and CodeQL
- Familiar with modern web frameworks and APIs
- Experience managing the vulnerability remediation process
- 5+ years in application security or related fields
Benefits
- Bi-annual performance bonuses
- Generous equity grants vested over 4 years
- Relocation assistance up to $15k
- Exposure to cutting-edge AI technologies
- Collaborative in-person work environment
- Ownership of the application security domain
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Mercor
Mercor builds a marketplace platform connecting expert talent to AI opportunities, supported by identity infrastructure, matching algorithms, and internal tools for data management. The company is hiring Software Engineers, Machine Learning Engineers, Fullstack Engineers, and Security Engineers to develop backend systems, ML models, cloud infrastructure, and distributed platforms.
- Website
- mercor.io
Likely interview questions
- Walk us through a real vulnerability you found in a production application—what was the flaw, how did you discover it, and how did you validate it was exploitable?
- Describe your experience with SAST/DAST tooling. Which tools have you used, and have you ever tuned or customized rules to reduce false positives or catch domain-specific flaws?