EngineerJobs.io
← Back to all jobs

Job Description

Mercor is building a platform where the application layer is the highest-priority security surface, and security needs to be embedded into day-to-day engineering. In this role, you will own application security end to end, from reviewing code and improving SDLC workflows to integrating security tooling into CI/CD and driving fixes to closure. The platform supports 300K+ experts and enterprise clients that handle sensitive AI training data.

Security Engineer, Application Security will work onsite in New York, NY and will bring 5+ years of professional experience with an application security focus. The compensation range is USD 130,000 - 400,000 per year.

What you’ll do

  • Embed security review workflows in the SDLC, performing PR-level analysis to catch authentication bugs, injection flaws, and business logic errors before changes ship
  • Integrate SAST/DAST pipelines into CI/CD to shift security left while keeping deploy velocity intact
  • Run vulnerability management with prioritization based on real exploitability rather than CVSS score
  • Define secure coding standards and guardrails that support safer patterns across a team of 50+ engineers
  • Develop threat models for new features and architecture changes, with special attention to AI data pipelines, payment flows, and multi-tenant boundaries
  • Operate the bug bounty program, including triaging HackerOne reports, validating findings, and driving remediation through to closure

Requirements

  • Have found and fixed real vulnerabilities in production applications, not only run scanners
  • Possess deep web application security knowledge, with OWASP Top 10 as a baseline and the ability to reason about attack chains and business logic flaws
  • Strength in at least one of Python, TypeScript, or Go, including the ability to review a PR and spot issues such as an auth bypass
  • Experience building or tuning SAST/DAST tooling, including familiarity with tools such as Semgrep, CodeQL, Snyk, and Burp
  • Understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
  • Experience managing a vulnerability pipeline from discovery through prioritization to verified remediation
  • Bring 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Technologies

  • Python, TypeScript, Go
  • Semgrep, CodeQL, Snyk, Burp
  • HackerOne
  • OWASP Top 10

Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus if you live within 0.5 miles of the office
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

Bonus points

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills, including penetration testing experience and an attacker mindset
  • Experience securing AI/ML applications, including model serving APIs, training data pipelines, and prompt injection defense
  • Familiarity with supply chain security such as dependency scanning and registry firewalls (Socket, Snyk)
  • Built custom security tooling that remains in active use by the team
  • Contributions to open source security projects or published vulnerability research

Similar Jobs