368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$130k – $400k per year
Location
In office (San Francisco, New York)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Mercor is an artificial intelligence infrastructure company headquartered in San Francisco, California, and founded in 2023. The company operates a platform that connects a global network of domain experts, including physicians, lawyers, and engineers, with AI labs to provide high-quality data for reinforcement learning from human feedback (RLHF) and model evaluation. It develops specialized benchmarks like APEX to measure model performance on economically valuable tasks and provides enterprises with tools to monetize their workflow data for AI training.

About Mercor

Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.

You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.

We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.

We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build:

  • Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship

  • SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys

  • Vulnerability management processes that prioritize by real exploitability, not CVSS score

  • Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers

  • Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries

  • Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure

What We're Looking For

  • You've found and fixed real vulnerabilities in production applications - not just run scanners

  • Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws

  • Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass

  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)

  • You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them

  • Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation

  • 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus

Bonus Points

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)

  • Offensive security skills - you've done penetration testing and can think like an attacker

  • Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense

  • Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)

  • You've built custom security tooling that a team still uses

  • Contributions to open source security projects or published vulnerability research

Why Mercor

  • The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.

  • AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.

  • Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.

  • See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.

    Benefits

    • Bi-annual performance bonus structure

    • Generous equity grant vested over 4 years

    • Up to $15k Relocation bonus

    • $10K housing bonus (if you live within 0.5 miles of our office)

    • $1.5K monthly stipend for meals

    • Free Equinox membership

    • $200 monthly laundry reimbursement

    • $200 monthly personal wellness reimbursement

    • Health, Dental, Vision insurance

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$13k – $29k per year (Estimated) • Remote • Full-Time • 3+ years exp • Krasnodar
DevOps
Git
Management
Jira
Apply
AI Engineer 1 day ago
$25k – $103k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Gurgaon
Python
SQL
Databases
Databricks
Microsoft Fabric
AI/ML
AI Agents
Embeddings
Gemini
Hallucination
LangChain
LangGraph
LLM
Multimodal AI
Prompt Engineering
PyTorch
RAG
Semantic Search
Spark
TensorFlow
Hugging Face
LLM Guardrails
LLMOps
OpenAI
Semantic Search
DevOps
AWS
Azure
CI/CD
Apply
$24k – $55k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Moscow
DevOps
AWS
Azure
SLI/SLO/SLA
Cybersecurity
GDPR
Management
Jira
ServiceNow
Apply
$18k – $46k per year (Estimated) • In office • Full-Time • Moscow
DevOps
Ansible
ArgoCD
AWS
CI/CD
Docker
GitLab CI
Helm
Kubernetes
OpenTofu
Terraform
Terragrunt
Yandex Cloud
GitLab
Apply
$114k – $237k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Lausanne
Java
Java
Micronaut
Spring Framework
Databases
Apache Kafka
DevOps
AWS
CI/CD
Docker
Kubernetes
Apply
$200k – $500k per year • Equity • In office • Full-Time • PhD • San Francisco
AI/ML
LLM
NLP
LLM Evaluation
Post-training
AI Agents
Apply
$130k – $500k per year • Equity • In office • Full-Time • New York
Python
TypeScript
JavaScript
Python
Django
FastAPI
Pydantic
Databases
DuckDB
MySQL
PostgreSQL
Redis
Snowflake
AI/ML
LangChain
LangGraph
LangSmith
LLM
AI Agents
Human-in-the-Loop
LLM Guardrails
Frontend
Next.js
React.js
Tailwind CSS
DevOps
Datadog
Kubernetes
Apply
$130k – $500k per year • Equity • In office • Full-Time • New York
Go
Python
Rust
AI/ML
Synthetic Data
Post-training
Apply
$130k – $500k per year • Equity • In office • Full-Time • 2+ years exp • New York
Apply
$130k – $500k per year • Equity • In office • Full-Time • New York
Python
Databases
PostgreSQL
DevOps
AWS
Apply
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
Senior ML Engineer 28 min ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • San Francisco
Go
JavaScript
Ruby
Scala
Apply
$360k – $530k per year • In office • Full-Time • Bachelor's Degree • San Francisco
MATLAB
Python
MATLAB
Simulink
AI/ML
OpenAI
Robotics
Digital Twin
Apply
$222k – $277k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Francisco
DevOps
CI/CD
Immutable Infrastructure
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.