SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Application Security

Mercor - San Francisco, CA, United States - In-office - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Mercor is an AI data company building infrastructure between human expertise and frontier AI models. The company operates a platform with 300K+ domain experts and enterprise clients, processing sensitive AI training data at scale. Mercor is a profitable Series C company valued at $10 billion. You will own application security across the platform, embedding security directly into the development lifecycle rather than operating as a scan-and-triage function. Your responsibilities include: - Embedding security review workflows into the SDLC with PR-level analysis to catch authentication bugs, injection flaws, and business logic errors before deployment - Building and integrating SAST/DAST pipelines into CI/CD to shift security left without slowing development velocity - Developing vulnerability management processes that prioritize by real exploitability rather than CVSS scores alone - Establishing secure coding standards and guardrails for a 50+ person engineering team - Creating threat models for new features and architecture changes, with particular focus on AI data pipelines, payment flows, and multi-tenant boundaries - Operating the bug bounty program, including triaging HackerOne reports, validating findings, and driving fixes to closure The role emphasizes using AI heavily in security work—building alongside AI code-gen tools, leveraging LLMs for code review and threat modeling, and automating repetitive work. You'll work in-person five days a week at the San Francisco headquarters, with first Fridays remote. REQUIREMENTS: - 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus - Demonstrated track record of finding and fixing real vulnerabilities in production applications - Deep understanding of web application security: OWASP Top 10 as baseline, with ability to think in terms of attack chains and business logic flaws - Strong proficiency in at least one of Python, TypeScript, or Go—able to read PRs and spot authentication bypasses - Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) - Understanding of modern web frameworks, APIs, and authentication patterns sufficient for threat modeling - Experience managing a vulnerability pipeline from discovery through prioritization to verified remediation BONUS QUALIFICATIONS: - Experience running or triaging a bug bounty program (HackerOne, Bugcrowd) - Offensive security skills and penetration testing experience - Experience securing AI/ML applications, including model serving APIs, training data pipelines, and prompt injection defense - Familiarity with supply chain security (dependency scanning, registry firewalls) - Custom security tooling built for team use - Open source security project contributions or published vulnerability research

Similar roles