Security Engineer, Application Security
Job Description
Mercor is building a platform where the application layer is the highest-priority security surface, and security needs to be embedded into day-to-day engineering. In this role, you will own application security end to end, from reviewing code and improving SDLC workflows to integrating security tooling into CI/CD and driving fixes to closure. The platform supports 300K+ experts and enterprise clients that handle sensitive AI training data.
Security Engineer, Application Security will work onsite in New York, NY and will bring 5+ years of professional experience with an application security focus. The compensation range is USD 130,000 - 400,000 per year.
What you’ll do
- Embed security review workflows in the SDLC, performing PR-level analysis to catch authentication bugs, injection flaws, and business logic errors before changes ship
- Integrate SAST/DAST pipelines into CI/CD to shift security left while keeping deploy velocity intact
- Run vulnerability management with prioritization based on real exploitability rather than CVSS score
- Define secure coding standards and guardrails that support safer patterns across a team of 50+ engineers
- Develop threat models for new features and architecture changes, with special attention to AI data pipelines, payment flows, and multi-tenant boundaries
- Operate the bug bounty program, including triaging HackerOne reports, validating findings, and driving remediation through to closure
Requirements
- Have found and fixed real vulnerabilities in production applications, not only run scanners
- Possess deep web application security knowledge, with OWASP Top 10 as a baseline and the ability to reason about attack chains and business logic flaws
- Strength in at least one of Python, TypeScript, or Go, including the ability to review a PR and spot issues such as an auth bypass
- Experience building or tuning SAST/DAST tooling, including familiarity with tools such as Semgrep, CodeQL, Snyk, and Burp
- Understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
- Experience managing a vulnerability pipeline from discovery through prioritization to verified remediation
- Bring 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
Technologies
- Python, TypeScript, Go
- Semgrep, CodeQL, Snyk, Burp
- HackerOne
- OWASP Top 10
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus if you live within 0.5 miles of the office
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Bonus points
- Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
- Offensive security skills, including penetration testing experience and an attacker mindset
- Experience securing AI/ML applications, including model serving APIs, training data pipelines, and prompt injection defense
- Familiarity with supply chain security such as dependency scanning and registry firewalls (Socket, Snyk)
- Built custom security tooling that remains in active use by the team
- Contributions to open source security projects or published vulnerability research