Security Engineer, Application Security
Mercor Inc
Application Security Engineer
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You'll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
What You'll Build
- Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
- SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
- Vulnerability management processes that prioritize by real exploitability, not CVSS score
- Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
- Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
- Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
What We're Looking For
- You've found and fixed real vulnerabilities in production applications - not just run scanners
- Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
- Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
- Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
- You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
- Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
- 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Bonus Points
- Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
- Offensive security skills - you've done penetration testing and can think like an attacker
- Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
- Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
- You've built custom security tooling that a team still uses
- Contributions to open source security projects or published vulnerability research
Why Mercor
- The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
- AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
- Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
- See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
$200k - $220k
...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our... ...gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified...ApplicationWork at officeLocal area$10 per hour
...and the environment? Come join us.All security disciplines work under the umbrella of... ...paved path and tooling that hundreds of engineers around the world rely on every day to ship... ...drift across our critical SaaS applications.Own security configuration for the SaaS...ApplicationWork at officeImmediate startRelocationRelocation packageFlexible hours$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and... ...CD pipelines with a strong focus on security.Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing...ApplicationFull time- ...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers... ...keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment. If you'...ApplicationFor contractorsRemote work
- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built... .... You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that our...ApplicationFull timeWork experience placementWork at officeRemote work
$266k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We... ...a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and mitigating...ApplicationWork at officeRemote workRelocation packageFlexible hours$146.3k - $257.7k
...join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems powering...ApplicationFull timeWork at officeLocal area- ...identity verification infrastructure where security isn't a layer we add later, it's core... ...ll work alongside experienced security engineers to defend Persona's people, devices,... ...Harden corporate infrastructure and SaaS applications against attack Translate endpoint...ApplicationFull timeFor contractorsInternshipWork at officeWork from homeRelocation packageMonday to FridayFlexible hours
$175k - $220k
About the RoleWe are looking for a highly technical Senior Security Engineer who is passionate about protecting data across modern SaaS,... ...continuously evolve Sigma’s data security capabilities across SaaS applications, cloud platforms, endpoints, collaboration tools, AI...ApplicationFull timeWork at office$268k - $321k
...Senior Security Engineer, Data Security San Francisco Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable... ...Secure data flows between cloud storage, pipelines, and application services so the secure path is the default path Define and...ApplicationLocal area- ...speeds. About You and The Role Product security at Zipline protects systems that... ..., and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific... ...large-scale production systems across application and cloud infrastructure. ~ Demonstrable...ApplicationLocal area
$188.75k - $242.68k
...Washington D.C., Raleigh, London, and Amsterdam.The Platform Security team (PlatSec) defends Plaid against attackers. We own laptop... ...stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified...ApplicationWork experience placementWork at officeLocal area- ...sophisticated cyber and AI-driven threats, securing their AI transformation. Our... ...We're looking for an AI Security Engineer to join our Red Team and help us push the... ...of AI systems, including text-based LLM applications and multimodal agentic systems ~ Extend...ApplicationWorldwide
- ...New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that... ..., age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified...ApplicationFull timeWork experience placementLocal area
$266k
...intelligence benefits all of humanity.The Security team protects OpenAI’s technology,... ...About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec... ..., genetic information, or other applicable legally protected characteristic. For additional...Work at officeLocal areaFlexible hours$232k - $290k
...join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest... ...numerous factors including, among other things, an individual applicant’s experience and qualifications for the position. This range...Full timeWork at officeLocal area$401k
...intelligence benefits all of humanity.The Security team protects OpenAI’s technology,... ...RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec... ..., genetic information, or other applicable legally protected characteristic. For additional...Work at officeLocal areaRemote workFlexible hours- ...discuss further. We are currently seeking a IT and Security Engineer to join a client in Salt Lake City UT and SFO CA. This is a... ...ISO 27001 and NIST CSF 2.0 frameworks and their practical application. ~ Hands-on experience with Okta, Google Workspace, and Jira...ApplicationFull timeLocal area
- ...expertise in Managed Infrastructure Services, Application Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most... ...market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure...ApplicationFull timeLocal area
$175k - $220k
About the RoleWe are looking for a highly technical Senior Security Engineer who thrives on building security capabilities from the ground... ...LLM SecurityDesign and implement security controls for AI applications, LLM-powered services, agents, and AI development workflows...ApplicationFull timeWork at office- ...expertise in Managed Infrastructure Services, Application Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most... ...comWe're looking for a Microsoft Security Engineer who brings curiosity, initiative, and a genuine...ApplicationFull time
$180k - $280k
...the sensitive data and privileged access they need to get issues fixed.You'll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you'll establish our...ApplicationShift work$130k - $200k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...experience such as with Python, Bash, Powershell.Applicant Safety Policy: Fraud and Third-Party RecruitersTo protect...ApplicationTemporary workLocal areaWorldwide$105.4k - $207.8k
Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber... ...and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected...ApplicationWork experience placementLocal areaRemote work$170k - $205k
...build with us at Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver... ...structured patch management program with clear SLAs for OS and application updates across all device platforms.Define and enforce...ApplicationTemporary work$141.6k - $212.4k
...creators to own their own destiny.Klaviyo is looking for a Senior Security Engineer to add to our growing Detection & Response Team. This is an... ...player with a strong, self-managing work ethicMassachusetts Applicants:It is unlawful in Massachusetts to require or administer a...Application- ...addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program... ...terraformOur Product Security lead talked about the Future Application Security EngineersOur Security Engineering lead talk about...ApplicationWork at officeRelocation3 days per week1 day per week
$230k - $390k
...led the product and design teams for Google Workspace. Security EngineerSecurity Engineering builds the foundations that let Sierra deliver... ...and improve detections and response workflows across applications, cloud infrastructure, identity, endpoints, and internal...ApplicationFull timeFlexible hours$10 per hour
...tier-1 queue here. Detection & Response engineers own their detections end to end: you write... ...your team is paged when they fire. The security team is spread across the globe with a... ...dedicated and engaged workforce. All qualified applicants will receive consideration for...ApplicationWork at officeLocal areaImmediate startRelocationRelocation packageFlexible hours$130k
About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security, infrastructure security, enterprise security, and security/compliance automation. This is a hands-on, high-impact role for...ApplicationFull timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Application Security. Be the first to apply!
- product security engineer San Francisco, CA
- cloud security engineer San Francisco, CA
- network security engineer San Francisco, CA
- security software engineer San Francisco, CA
- security engineer San Francisco, CA
- IT security engineer San Francisco, CA
- security engineering manager San Francisco, CA
- aws cloud security engineer San Francisco, CA
- senior security operations engineer San Francisco, CA
- dlp security engineer San Francisco, CA


