Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Security Engineer, Application Security role.
Rezi rewrites your resume against Mercor's job description. Free.

Tailor your resume to this Security Engineer, Application Security role.
Rezi rewrites your resume against Mercor's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Security Engineer, Application Security posting at Mercor — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Security Engineer, Application Security posting at Mercor — free, in seconds.
About the Role
You'll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you'll fit in here.
Responsibilities
- Build security review workflows embedded in the SDLC, including PR-level analysis for auth bugs, injection flaws, and business logic errors.
- Integrate SAST/DAST pipelines into CI/CD to shift security left without slowing down deploys.
- Develop vulnerability management processes that prioritize by real exploitability, not CVSS score.
- Establish secure coding standards and guardrails for over 50 engineers.
- Create threat models for new features and architecture changes, focusing on AI data pipelines, payment flows, and multi-tenant boundaries.
- Manage bug bounty program operations, including triaging HackerOne reports, validating findings, and driving fixes to closure.
Requirements
- Proven experience finding and fixing real vulnerabilities in production applications, beyond just running scanners.
- Deep understanding of web application security, including OWASP Top 10, attack chains, and business logic flaws.
- Proficiency in at least one of Python, TypeScript, or Go for code review and vulnerability identification.
- Experience building or tuning SAST/DAST tooling (e.g., Semgrep, CodeQL, Snyk, Burp).
- Strong understanding of modern web frameworks, APIs, and authentication patterns for effective threat modeling.
- Experience managing a vulnerability pipeline from discovery through prioritization to verified remediation.
- 5+ years of professional experience in application security, security engineering, or software engineering with a security focus.
Skills
- Application Security
- Security Engineering
- Software Engineering
- Web Application Security
- OWASP Top 10
- Attack Chains
- Business Logic Flaws
- Python
- TypeScript
- Go
- SAST/DAST Tooling
- Semgrep
- CodeQL
- Snyk
- Burp
- Web Frameworks
- APIs
- Authentication Patterns
- Threat Modeling
- Vulnerability Management
- Bug Bounty Programs
- AI/ML Security
- Supply Chain Security
- Custom Security Tooling
- Open Source Security Projects
- Vulnerability Research
- AI Code-gen Tools
- LLMs
- Prompt Injection Defense
Location
- San Francisco
- NYC
- London
Work Type
- In-person
- Full-time
Experience Level
- 5+ years of professional experience
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
About the Company
- Mercor is a leading AI data company, building the layer between human expertise and frontier models.
- Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models.
- Mercor's APEX benchmark family measures AI's real-world impact on professional work.
- Mercor Enterprise brings this same infrastructure to Fortune 500 companies, helping companies capture how their best people actually work and translating that expertise directly back into agents.
- Mercor is creating a new category of work where expertise powers AI advancement.
- Mercor is a profitable Series C company valued at $10 billion.