Skip to content
NEXTMOVEFDE careers · United States

Security Engineer, Application Security

AI summary of the role

Own application security end-to-end at a fast-growing AI marketplace company.

What you’ll do

  • Embed security review workflows in the SDLC with PR-level analysis to catch auth bugs, injection flaws, and business logic errors before they ship
  • Build SAST/DAST pipelines integrated into CI/CD to shift security left without slowing deploys
  • Manage vulnerability management processes prioritizing by real exploitability, not CVSS score
  • Create secure coding standards and guardrails for 50+ engineers

What you’ll bring

  • 5+ years professional experience in application security, security engineering, or software engineering with strong security focus
  • Deep understanding of web application security including OWASP Top 10, attack chains, and business logic flaws
  • Strong in at least one of Python, TypeScript, or Go
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar)

Technologies

Python · TypeScript · Go · Semgrep · CodeQL · Snyk · Burp · SAST · DAST · HackerOne

About Mercor

Marketplace matching domain experts (doctors, lawyers, scientists, engineers) with AI labs to generate post-training data, evaluations, and reinforcement learning signal.

Series C

Source and classification

Internal deployment & tooling · Evidence for this classification:

valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays
More from the job description

About Mercor Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. [... source excerpt omitted ...] accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here. We're in-person five days a week at our SF headquarters, with first Fridays remote. What You'll Build: Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys Vulnerability management processes that prioritize by real exploitability, not CVSS score Secure coding standards and guardrails t [... source excerpt omitted ...] g bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure What We're Looking For You've found and fixed real vulnerabilities in production applications - not just run scanners Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them Experience managing a vulnerab

How jobs are selected

Employer postings · Data from · Sources