Page 1
Loading more openings…
You've reached the end of the list.
Security Engineer, Cloud Infrastructure
Mercor · United States
Pay
$130k–400k
Setting
Remote
ABOUT MERCOR
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own cloud and infrastructure security at a company where tenant isolation is a critical enterprise requirement. Mercor's customers - including frontier AI labs - need hard guarantees that their data stays within strict boundaries. This is not a compliance checkbox role. You'll architect multi-account AWS isolation, harden Kubernetes clusters, deploy cloud security posture management, and build the infrastructure that lets Mercor serve enterprise clients who demand the highest security bar.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate infrastructure review and policy authoring, and automating away the repetitive work that slows infrastructure security down. If you'd rather write a Terraform module than fill out a spreadsheet, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
WHAT YOU'LL BUILD:
- Multi-account AWS tenant isolation architecture - dedicated accounts, SCPs, network boundaries, and data segregation for enterprise clients
- Cloud security posture management using Wiz CSPM - continuous monitoring, misconfiguration detection, and automated remediation
- Kubernetes security hardening - pod security standards, network policies, secrets management, and runtime protection
- Infrastructure-as-code security guardrails - Terraform/CloudFormation policies that prevent insecure deployments before they reach production
- IAM architecture and least-privilege access controls across AWS, Snowflake, and internal services
- Incident response infrastructure - logging pipelines, forensic readiness, and blast radius containment
WHAT WE'RE LOOKING FOR
- Deep AWS security expertise - you've architected multi-account strategies, written SCPs, and hardened production environments
- Experience with Kubernetes security in production - not just tutorials, you've secured real clusters running real workloads
- Strong infrastructure-as-code skills - Terraform, CloudFormation, or Pulumi - you think in code, not console clicks
- Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar) - deploying, tuning, and driving remediation
- Understanding of network security at the cloud level - VPCs, security groups, transit gateways, PrivateLink
- You've designed tenant isolation for multi-tenant SaaS - data segregation, compute isolation, network boundaries
- 5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus
BONUS POINTS
- Experience with Snowflake security - schema-level isolation, access controls, data sharing governance
- Familiarity with container runtime security (Falco, SentinelOne Cloud Workload Protection, or similar)
- Offensive cloud security skills - you've exploited misconfigurations and understand the attacker's perspective
- Experience building compliance-ready infrastructure (SOC 2, ISO 27001, FedRAMP)
- You've handled cloud security incidents - forensics, containment, and root cause analysis in AWS
- Contributions to open source infrastructure security tools
WHY MERCOR
- The deliverable is concrete. Enterprise clients require tenant isolation as a baseline. You'll build infrastructure that directly enables the business.
- AI-native infrastructure security. You'll use frontier AI tools daily - for policy authoring, misconfiguration analysis, and anything that benefits from an AI co-pilot.
- Ownership from day one. You'll own the entire cloud security domain - from AWS architecture to Kubernetes hardening to CSPM operations.
- See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Listed by Mercor for a position based in the United States. Employers on this board attest they are hiring domestically.
Security Engineer, Application Security
Mercor · United States
Pay
$130k–400k
Setting
Remote
ABOUT MERCOR
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
WHAT YOU'LL BUILD:
- Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship
- SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys
- Vulnerability management processes that prioritize by real exploitability, not CVSS score
- Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers
- Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries
- Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure
WHAT WE'RE LOOKING FOR
- You've found and fixed real vulnerabilities in production applications - not just run scanners
- Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws
- Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass
- Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)
- You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them
- Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation
- 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus
BONUS POINTS
- Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
- Offensive security skills - you've done penetration testing and can think like an attacker
- Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense
- Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk)
- You've built custom security tooling that a team still uses
- Contributions to open source security projects or published vulnerability research
WHY MERCOR
- The problem is real. Application security at scale is hard - you'll build defenses that matter across a fast-moving platform.
- AI-native AppSec. You'll use frontier AI tools daily - for code review, vulnerability analysis, and anything that benefits from an AI co-pilot.
- Ownership from day one. You'll own the entire application security domain - from code review processes to CI/CD security to bug bounty operations.
- See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Listed by Mercor for a position based in the United States. Employers on this board attest they are hiring domestically.
Software Engineer, Frontier Data Products
Mercor · United States
Pay
$130k–500k
Setting
Remote
ABOUT MERCOR
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
ABOUT MERCOR
Mercor is defining the future of work. We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development.
Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society.
Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our new San Francisco headquarters.
About the Role
Frontier AI companies are increasingly bottlenecked on expert judgment and high-quality data workflows. This team builds the production systems that capture, coordinate, and validate that work at scale — directly between a customer request and the output that ships.
These are long-running, stateful systems. A single job can stay live for days, interleaving automated steps, model inference, and expert review. A step marked "done" can be reopened, re-reviewed, and redone — so "completed" is not always final, state has to tolerate late mutation, and correctness has to survive humans and models disagreeing with each other.
This is a backend systems and orchestration problem: distributed state machines, not pipelines. The architecture is not set. Early engineers will decide what it becomes, and the loop between "I shipped this" and "this mattered" is short.
What You'll Do
- Design services and state models for multi-stage workflows that fan out across automated processing and expert reviewers, then reconcile results into a coherent whole
- Build orchestration primitives — retries, failure recovery, idempotency, auditable state transitions — for jobs that run far longer than a request and can be partially redone after the fact
- Integrate model inference into production workflows without sacrificing debuggability or human oversight
- Build the APIs and tooling that let product, operations, and ML teams operate, debug, and trust these systems at scale
- Own reliability and observability for workflows where a silent failure means a corrupted result, not just a 500
What Makes This Role Different
- You are building the core infrastructure that sits directly between customer requests and the outputs that ship — not internal tooling, not a support system
- This product area is young and strategically central; early engineers are deciding the architecture, not inheriting it
- The inputs are non-deterministic by nature — you are building durable orchestration over humans and models that can disagree with each other on hour 40 of a multi-stage job
Day-to-Day
- Moving fast on genuinely hard systems problems — ambiguity is the default, not the exception
- Working closely with product, operations, and ML teams to translate a tangle of constraints into clean system design
- Debugging complex stateful workflows where the failure surface spans automated steps, model calls, and human reviewers
- Owning your systems end-to-end: design, ship, operate, improve
What We're Looking For
- Production backend experience with strong opinions about what ages well and why
- Sharp instincts for system design, service boundaries, and where to put complexity — and where to refuse it
- Fluency with the distributed systems toolkit: async workflows, queues, idempotency, retries, and long-running jobs as practice, not resume line items
- Ability to take ambiguous product, operational, and ML constraints and turn them into a system that is clean and debuggable
- Comfort working in Python on AWS with Postgres; experience with Temporal or similar workflow engines is a plus
You're likely someone who:
- Gets frustrated by systems that are hard to debug and takes that personally enough to fix it
- Has strong opinions about where state should live and can defend them in a design review
- Moves fast but doesn't treat reliability as someone else's problem
- Wants your work to have a short, visible line to outcomes that actually matter to customers
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Listed by Mercor for a position based in the United States. Employers on this board attest they are hiring domestically.
Select a role
The full posting opens here — pay, setting and the full description, without leaving the list.