Security Engineer, Application Security

Mercor

$150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in application security, security engineering, or software engineering with a security focus
  • Proficient in at least one programming language (Python, TypeScript, or Go)
  • Deep knowledge of web application security, including understanding attack chains and business logic flaws
  • Experience with SAST/DAST tooling like Semgrep, CodeQL, or Snyk
  • Ability to construct and manage a vulnerability management pipeline
  • Hands-on experience fixing real vulnerabilities in production applications
  • Familiarity with modern web frameworks, APIs, and authentication patterns

Responsibilities

  • Embed security review workflows in the SDLC to identify vulnerabilities before deployment
  • Integrate SAST/DAST tools into CI/CD pipelines to enhance security without impeding development
  • Establish vulnerability management processes focusing on real exploitability
  • Develop and enforce secure coding standards and guardrails for engineering teams
  • Create and implement threat models for new features, especially related to AI and payment systems
  • Manage bug bounty program operations by triaging reports and ensuring remediation

Benefits

  • Gain ownership of the application security domain from day one
  • Utilize cutting-edge AI tools for security processes
  • Impact the security posture of a large-scale platform serving elite clients
  • Collaborate with AI labs to stay ahead of industry developments
  • Work in an in-person environment with limited remote flexibility
Full Job Description
You9ll own application security at a company where the app layer is the highest-priority security surface. This is not a scan-and-triage role. You9ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you9d rather write a CodeQL query than file a Jira ticket, you9ll fit in here. We9re in-person five days a week at our SF headquarters, with first Fridays remote. What You9ll Build: 3 Security review workflows embedded in the SDLC - PR-level analysis that catches auth bugs, injection flaws, and business logic errors before they ship 3 SAST/DAST pipelines integrated into CI/CD - shifting security left without slowing down deploys 3 Vulnerability management processes that prioritize by real exploitability, not CVSS score 3 Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers 3 Threat models for new features and architecture changes - especially around AI data pipelines, payment flows, and multi-tenant boundaries 3 Bug bounty program operations - triaging HackerOne reports, validating findings, and driving fixes to closure What We9re Looking For 3 You9ve found and fixed real vulnerabilities in production applications - not just run scanners 3 Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws 3 Strong in at least one of Python, TypeScript, or Go - you can read a PR and spot the auth bypass 3 Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) 3 You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them 3 Experience managing a vulnerability pipeline - from discovery through prioritization to verified remediation 3 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus Bonus Points 3 Experience running or triaging a bug bounty program (HackerOne, Bugcrowd) 3 Offensive security skills - you9ve done penetration testing and can think like an attacker 3 Experience securing AI/ML applications - model serving APIs, training data pipelines, prompt injection defense 3 Familiarity with supply chain security - dependency scanning, registry firewalls (Socket, Snyk) 3 You9ve built custom security tooling that a team still uses 3 Contributions to open source security projects or published vulnerability research Benefits 3 Bi-annual performance bonus structure 3 Generous equity grant vested over 4 years 3 Up to $15k Relocation bonus 3 $10K housing bonus (if you live within 0.5 miles of our office) 3 $1.5K monthly stipend for meals 3 Free Equinox membership 3 $200 monthly laundry reimbursement 3 $200 monthly personal wellness reimbursement 3 Health, Dental, Vision insurance

Similar Jobs

More Jobs at Mercor

More Information Technology Jobs

Find similar Security Engineer, Application Security jobs: