bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesMercorSecurity Engineer, Application Security

Security Engineer, Application Security

Mercor · San Francisco or NYC · Remote · Active · Ashby

Job facts

FieldValue
CompanyMercor
TitleSecurity Engineer, Application Security
Normalized title-
Department / teamEngineering / Engineering
LocationSan Francisco, CA, United States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Mercor.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in San Francisco.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyMercor
Source8a2bb184-0550-471f-814d-47b207e73710
ATS providerAshby

Description

About Mercor Mercor's mission is to organize human intelligence to power the AI economy. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays remote. What You'll Build: Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys Vulnerability management processes that prioritize by real exploitability, not CVSS score Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure What We're Looking For You've found and fixed real vulnerabilities in production applications - not just run scanners Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus Bonus Points Experience running or triaging a bug bounty program (HackerOne, Bugcrowd) Offensive security skills - you've done penetration testing and can think like an attacker Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk) You've built custom security tooling that a team still uses Contributions to open source security projects or published vulnerability research Why Mercor The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform. AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot. Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations. See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market. Benefits Bi-annual performance bonus structure Generous equity grant vested over 4 years Up to $15k Relocation bonus $10K housing bonus (if you live within 0.5 miles of our office) $1.5K monthly stipend for meals Free Equinox membership $200 monthly laundry reimbursement $200 monthly personal wellness reimbursement Health, Dental, Vision insurance

Full job record

Job ID7d40fc5930e106bfc307a0f49d64df56add511ed
Org ID3454cf47-ee94-47fc-918e-00dca2cf958a
Source ID8a2bb184-0550-471f-814d-47b207e73710
Board ID8a2bb184-0550-471f-814d-47b207e73710
Providerashby
Provider Job Keycf6fcf5a-6348-4d60-beb3-43333a2c2bb9
TitleSecurity Engineer, Application Security
Normalized Title
Statusactive
Activeyes
Location TextSan Francisco or NYC
DepartmentEngineering
TeamEngineering
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
RegionCA
CitySan Francisco
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/mercor/cf6fcf5a-6348-4d60-beb3-43333a2c2bb9
Apply URLhttps://jobs.ashbyhq.com/mercor/cf6fcf5a-6348-4d60-beb3-43333a2c2bb9/application
First Seen At2026-05-29 06:25:55Z
Last Seen At2026-06-06 09:21:37Z
Last Checked At2026-06-06 09:21:37Z
Last Changed At2026-05-29 06:25:55Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=mercor/date=2026-06-06/2026-06-06T09-21-01-699Z-54895e1da84fc7c39f2fb10eec58ccde13eafa9d3a21906c65077fbb39cfaabf.json
Event Fields
{
  "content_hash": "8275f5f5c59b44aaa2875f31fd5fcb69f7e62781030838d023b89c3fe542be96",
  "source_hash": "8dbca59825109d28c2444d2b31b88f648b9abdbe7d9baec48f69fc122c5d103d",
  "last_changed_at": "2026-05-29T06:25:55.233Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "San Francisco",
    "city": "San Francisco",
    "region": "CA",
    "country": "United States",
    "is_remote": true,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T09:21:37.650Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "San Francisco",
      "city": "San Francisco",
      "region": "CA",
      "country": "United States",
      "is_remote": true,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "cf6fcf5a-6348-4d60-beb3-43333a2c2bb9",
  "team": "Engineering",
  "title": "Security Engineer, Application Security",
  "jobUrl": "https://jobs.ashbyhq.com/mercor/cf6fcf5a-6348-4d60-beb3-43333a2c2bb9",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/mercor/cf6fcf5a-6348-4d60-beb3-43333a2c2bb9/application",
  "isListed": true,
  "isRemote": false,
  "location": "San Francisco or NYC",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Engineering",
  "publishedAt": null,
  "workplaceType": null,
  "employmentType": "FullTime",
  "secondaryLocations": [
    {
      "location": "New York City"
    }
  ]
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/7d40fc5930e106bfc307a0f49d64df56add511ed?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/3454cf47-ee94-47fc-918e-00dca2cf958aJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/8a2bb184-0550-471f-814d-47b207e73710JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/7d40fc5930e106bfc307a0f49d64df56add511ed/eventsJSON