Security Engineer, Application Security
Mercor Alabaster
About Mercor Mercor's mission is to organize human intelligence to power the AI economy. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $3 million a day. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You'll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays remote.
What You'll Build:
What You'll Build:
- Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
- SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
- Vulnerability management processes that prioritize by real exploitability, not CVSS score
- Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
- Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
- Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
- You've found and fixed real vulnerabilities in production applications - not just run scanners
- Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
- Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
- Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
- You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
- Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
- 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
- Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
- Offensive security skills - you've done penetration testing and can think like an attacker
- Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
- Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
- You've built custom security tooling that a team still uses
- Contributions to open source security projects or published vulnerability research
- The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
- AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
- Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
- See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer, Application Security in New York, NY vacancy
- ...fast-growing fintech company in the U.S. is seeking a Senior Security Engineer to enhance security within their innovative platform. This remote role involves leading security initiatives across application and cloud environments, conducting vulnerability assessments,...ApplicationRemote work
$165k - $242k
...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers... ...keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment. If you'...ApplicationTemporary workFor contractorsRemote workFlexible hours- ...Security Engineer – Application Security Fragomen is seeking a Security Engineer – Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh. We are looking for professionals who are passionate about security, capable...Application
$104k - $156k
...Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and... ...Preferred qualifications: ~ Experience securing cloud-native applications / SaaS solutions and networks. ~ Familiarity with...ApplicationRemote work- ...financial technology company in New York is seeking a Senior Security Engineer to create a security foundation that scales trust to... ...Ideal candidates should have over 6 years of cybersecurity experience and hands-on cloud application security skills. #J-18808-Ljbffr...Application
$165k - $185k
...winter holidays). About the Role Betterment is hiring a Sr. Security Engineer, Corporate Information Security to be a principal member of... .... What happens next We’ll take a few weeks to review all applications. If we’d like to spend more time with you, we’ll reach out...ApplicationTemporary workFor contractorsSummer holidayWork at officeLocal areaFlexible hours$150k - $200k
...Senior Security Engineer - Application Security New York, NY About the Role This is an opportunity to join K's critical InfoSec team as a Senior Security Engineer and operate with foresight in protecting our infrastructure, applications, cloud security, and customer...ApplicationFull timeWork at officeLocal area$195k - $240k
Here at Datadog, we think about offensive security a little bit differently. We embrace... ...environment, and we expect our offensive engineers to build the tooling that makes that... ...manage complexity at scale. It brings applications, infrastructure, data, models, and security...ApplicationWork at office- ...The Role We are seeking an experienced Security Engineer with a specialization in product security to join our team. As a strategic partner... ...immediate impact by leveraging your expertise in cloud and application security. This role is pivotal in reducing risk across our AWS...ApplicationImmediate start
$167.5k - $226.3k
...Senior Security Engineer (AI Security) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual... ...security architecture and design standards across Justworks applications and infrastructure to promote a standardized set of security...ApplicationCasual workWork at officeLocal area$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and... ...pipelines with a strong focus on security. Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing...ApplicationFull time$145k - $155k
...solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and... ...network protocols, operating systems, application layer protocols, and security best...ApplicationWeekday work$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits... ...robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and...ApplicationWork at officeRemote workRelocation package$100k - $140k
...keep reading - this may be your next great opportunity. As a Security Engineer, you will be part of BlackCloak’s internal technology team... ...Trust principles into new programs and architecture designs. Application Security (Support) Support application security program strategy...ApplicationFull timeTemporary workRemote workHome officeFlexible hoursShift work$165k - $215k
...us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network... ...by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience...ApplicationTemporary workWork at officeLocal areaRemote work- ...our journey to create a better future of work with AI. About the role This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems powering some...ApplicationFull timeWork at officeLocal areaFlexible hours
- ...Security Engineer (Infrastructure Security) About 1mind 1mind is a platform that deploys multimodal Superhumans for revenue teams. These... ...common vulnerabilities, and practical defenses across infra and application layers. 5+ years building and operating core infrastructure...ApplicationFull timeRemote workShift work
$100k - $120k
...Harris Computer is seeking an Expert Security Engineer to drive proactive security initiatives. This remote position in Canada focuses on... ...minimum of 5 years in cybersecurity and proven expertise in application security. Responsibilities include leading penetration tests...ApplicationRemote work$192k - $278k
...unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted.... .... Position We are looking for a Staff Security Engineer to found and lead the DevSecOps function within...ApplicationImmediate startRemote work$164.8k - $228.4k
...Senior Security Engineer – Data Security Upstart’s Information Security team is dedicated to advancing security practices that enhance... ...production‑quality systems such as APIs, services, or internal web applications. Experience launching new security capabilities from 0 to 1...ApplicationCurrently hiringLocal areaRemote work- ...An innovative AI solutions provider based in New York is seeking a Senior Security Engineer to enhance security measures for their cutting-edge applications. In this role, you will automate security processes, address vulnerabilities, and ensure compliance with industry...Application
$89.3k - $130k
...American Specialty Health Incorporated is looking for an Application Security Engineer II to enhance their Information Security team. The role focuses on protecting information assets from cybersecurity threats, ensuring compliance, and coordinating security measures across...ApplicationRemote workWork from homeHome office- ...crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by... ...About the Opportunity Responsibilities Data Security (Optional Focus Area) Develop and... ...with security data models, detection rule engines, or in-house security product development...ApplicationWork at office
- Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry‑leading security systems... ..., age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider...ApplicationWork experience placementLocal area
$135.48k - $227.7k
...build for the long term. About the role: The Senior Security Engineer I - Enterprise Security is responsible for building, operating... ...of vulnerabilities and misconfigurations in systems and applications. * Mentor engineers in the Security team to grow their domain...ApplicationFull timeRemote workRelocation packageFlexible hours- -Core Specialty is seeking a Senior Azure Cyber Security Engineer to serve as a hands-on technical leader and subject matter expert within... ...operating security controls across Azure, identity, endpoint, cloud application, and network security domains. This role operates in a fast-...ApplicationTemporary workWork at officeLocal areaRemote workRelocationWork visaFlexible hours
$222k - $278k
...A code security company is looking for a Senior Security Engineer to enhance product security. This role involves collaborating with engineering teams to ensure secure application development and infrastructure management. Ideal candidates will have 7+ years of experience...ApplicationWork at office- ...A technology company based in New York seeks a Product Security Engineer to embed security practices into their development processes. Your... ...are met. Ideal candidates will have strong experience in Application Security and Cloud Security, as well as a solid understanding...Application
$204k - $240k
....00 - $240,000.00 What's the role? Etsy is seeking a Staff Security Engineer to join our Security Operations team. As part of the larger... ...role in protecting and responding to threats to our data, applications, systems, and infrastructure. Security Operations is responsible...ApplicationFull timeWork at officeLocal areaVisa sponsorshipFlexible hours- ...About the Role Sigma is seeking a Senior Security Engineer to join our growing Cyber Security team. As a Senior Security Engineer, you... ...to embed DevSecOps practices into CI/CD pipelines and application development. Proactively identify and remediate misconfigurations...ApplicationFull timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Application Security. Be the first to apply!
Related searches
- endpoint security engineer New York, NY
- senior cloud security engineer New York, NY
- product security engineer New York, NY
- security infrastructure engineer New York, NY
- lead security engineer New York, NY
- entry level security engineer New York, NY
- security engineering manager New York, NY
- sr security engineer New York, NY
- security solutions engineer New York, NY
- senior security operations engineer New York, NY



