Mercor
Security Engineer, Cloud Infrastructure
About this role
Mercor is seeking a Security Engineer specialized in Cloud Infrastructure to enhance security measures for enterprise clients, focusing particularly on tenant isolation. The role involves architecting and hardening AWS and Kubernetes systems while leveraging AI tools to optimize security practices.
What you'll do
- Design multi-account AWS isolation architecture
- Implement cloud security posture management
- Harden Kubernetes clusters for production environments
- Establish infrastructure-as-code security guardrails
- Manage IAM architecture and controls
- Develop incident response infrastructure
What they're looking for
- Deep AWS security expertise
- Kubernetes security experience
- Infrastructure-as-code proficiency (Terraform, CloudFormation)
- Familiarity with CSPM platforms
- Network security understanding at the cloud level
- Tenant isolation design experience
- 5+ years in cloud security or related fields
Benefits
- Work on concrete deliverables for enterprise clients
- Daily use of AI tools for security enhancements
- Ownership of the entire cloud security domain
- Collaboration with leading AI labs
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Mercor
Mercor builds a marketplace platform connecting expert talent to AI opportunities, supported by identity infrastructure, matching algorithms, and internal tools for data management. The company is hiring Software Engineers, Machine Learning Engineers, Fullstack Engineers, and Security Engineers to develop backend systems, ML models, cloud infrastructure, and distributed platforms.
- Website
- mercor.io
Likely interview questions
- Walk us through how you'd architect multi-account AWS isolation for a multi-tenant SaaS platform serving enterprise AI labs. What SCPs, network boundaries, and data segregation strategies would you implement?
- Describe your experience hardening Kubernetes clusters in production. How would you approach pod security standards, network policies, and secrets management for a security-critical environment?