# Security Engineer, Application Security at Mercor

- Company: Mercor
- What the company does: Mercor is organizing human intelligence to power the AI economy. We are powering frontier research, AI benchmarks, and AI agent training at scale for the top AI labs and enterprises. Backed by General Catalyst and Menlo.
- Company website: https://mercor.com/
- Type: Startups
- Level: Mid level
- Location: San Francisco
- Work setup: On-site
- Pay: $130K to $400K base salary per year (USD)
- Posted: 2026-09-04
- Apply by: 2026-10-19
- Apply: https://jobs.ashbyhq.com/mercor/cf6fcf5a-6348-4d60-beb3-43333a2c2bb9
- Page: https://www.1752.vc/careers/jobs/mercor-security-engineer-application-security/

## About the role

You've found and fixed real vulnerabilities in production applications - not just run scanners Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws

## What they're looking for

- You've found and fixed real vulnerabilities in production applications - not just run scanners
- Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
- Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
- Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
- You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
- Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation

Tags: Security
