Skip to content
MercorMercor

Security Engineer, Cloud Infrastructure

Designs and implements cloud security architectures including multi-account AWS isolation, Kubernetes hardening, and CSPM with Wiz for enterprise tenant separation. Requires 5+ years in cloud/infrastructure security, IaC expertise, and production experience.

About the job

What You'll Build

  • Multi-account AWS tenant isolation architecture - dedicated accounts, SCPs, network boundaries, and data segregation for enterprise clients
  • Cloud security posture management using Wiz CSPM - continuous monitoring, misconfiguration detection, and automated remediation
  • Kubernetes security hardening - pod security standards, network policies, secrets management, and runtime protection
  • Infrastructure-as-code security guardrails - Terraform/CloudFormation policies that prevent insecure deployments before they reach production
  • IAM architecture and least-privilege access controls across AWS, Snowflake, and internal services
  • Incident response infrastructure - logging pipelines, forensic readiness, and blast radius containment

What We're Looking For

  • Deep AWS security expertise - you've architected multi-account strategies, written SCPs, and hardened production environments
  • Experience with Kubernetes security in production - not just tutorials, you've secured real clusters running real workloads
  • Strong infrastructure-as-code skills - Terraform, CloudFormation, or Pulumi - you think in code, not console clicks
  • Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar) - deploying, tuning, and driving remediation
  • Understanding of network security at the cloud level - VPCs, security groups, transit gateways, PrivateLink
  • You've designed tenant isolation for multi-tenant SaaS - data segregation, compute isolation, network boundaries
  • 5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus

Bonus Points

  • Experience with Snowflake security - schema-level isolation, access controls, data sharing governance
  • Familiarity with container runtime security (Falco, SentinelOne Cloud Workload Protection, or similar)
  • Offensive cloud security skills - you've exploited misconfigurations and understand the attacker's perspective
  • Experience building compliance-ready infrastructure (SOC 2, ISO 27001, FedRAMP)
  • You've handled cloud security incidents - forensics, containment, and root cause analysis in AWS
  • Contributions to open source infrastructure security tools

Skills

AWS, Kubernetes, Terraform, Wiz, Cspm, IAM, Scps, Vpc, Security Groups, Snowflake, Falco

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

OpenAI

OpenAI

San Francisco, CA
Protective Intelligence & Threat Analyst
$126k+/yrHybrid5+ YOESecurity Engineering

Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.

Applied Intuition

Applied Intuition

Sunnyvale, CA

System Safety Engineer, Mining/Industrial
$125k+/yrOn-site5+ YOESecurity Engineering

Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.