# Security Engineer at Merge

- Company: Merge
- What the company does: Merge is the infrastructure layer for production AI. One platform connects your products and agents to every API, tool, and LLM they need to run at scale. Backed by Accel and NEA.
- Company website: https://merge.dev/
- Type: Startups
- Level: Mid level
- Location: New York, NY; San Francisco, CA
- Work setup: On-site
- Pay: $165K to $200K base salary per year (USD)
- Posted: 2026-09-09
- Apply by: 2026-10-24
- Apply: https://jobs.ashbyhq.com/merge/328f6431-aad9-4a63-9614-09ad9a762dd8
- Page: https://www.1752.vc/careers/jobs/merge-security-engineer/

## About the role

Own product and application security across Merge's platform: APIs, integrations, agent tooling, and AI-powered features Conduct security reviews, threat modeling, and code reviews with a focus on application-layer vulnerabilities (OWASP Top 10, injection, auth flaws, insecure deserialization, etc.)

## What they're looking for

- 3–6+ years of security engineering experience with a strong focus on product or application security
- Deep familiarity with application security concepts: OWASP, common vulnerability classes, secure API design, auth and authorization patterns
- Experience conducting threat modeling and secure code reviews
- Hands-on experience with application security tooling (SAST, DAST, SCA) and integrating security into CI/CD pipelines
- Experience with and a desire to code in at least one major programming language. You should be comfortable reading and writing code, not just running scanners
- Experience in a SaaS or API-driven environment, familiarity with multi-tenant systems and the security challenges they present

Tags: Engineering
