Security Expert | $90-$110/hr Remote
Overview
Mercor is building high-fidelity simulated environments to train AI models on real-world procurement workflows. We're seeking security and vendor-risk professionals to create and validate security-review tasks within these simulations, helping to improve AI evaluation accuracy.
What You'll Do4
- 1Evaluate simulated SOC 2 reports, security questionnaires, and penetration-test evidence against a buyer's security standard.
- 2Identify scope mismatches and expired bridge letters that a cursory review would overlook.
- 3Develop detailed rubrics and golden responses that reflect how an experienced security reviewer would assess a request or renewal.
- 4Assess data-handling and sub-processor risk for vendors dealing with sensitive information.
Requirements3
- 1At least 8 years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
- 2Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
- 3Strong written communication skills with the ability to produce structured, rubric-style feedback.
Who Should Apply
This role is ideal for seasoned security reviewers or vendor-risk professionals who enjoy breaking down complex compliance artifacts into clear evaluation criteria. You should be comfortable creating structured rubrics and have a knack for catching subtle gaps in evidence.
Salary Insight
Pay ranges from $90.00 to $110.00 per hour.
Application Tip
When applying, include a brief example of a SOC 2 report or pen-test finding you analyzed and how you would create a rubric to assess it. This will demonstrate your fit for the task-authoring aspect of the role.
Similar open positions
Explore active roles that match your skills and interests.
Mercor
VerifiedCybersecurity Experts | $70-$90/hr Remote
Mercor is teaming up with a premier AI research lab to recruit seasoned cybersecurity professionals for a short-term, high-impact project. In this role, you'll leverage your expertise in low-level systems programming and security vulnerability classification to help train AI models in threat detection and reasoning. The engagement starts with a paid work trial and could extend into a roughly two-month project, all fully remote.
Mercor
VerifiedProcurement Expert | $70-$100/hr Remote
Mercor is seeking senior procurement professionals to help build realistic, high-fidelity simulated environments for training AI on real-world procurement workflows. This is a contract role for a leading spend-management technology company, paying $70-$100 per hour. You'll leverage your deep vendor management experience to author tasks and rubrics that mirror how procurement teams vet new vendors and handle contract renewals.
Micro1
VerifiedCyber Security Analyst | $20-$80/hr Remote
This role lets you put your cybersecurity expertise to work in a unique way—helping train next-generation AI systems. You won't need any prior AI experience; your domain knowledge in security is what counts. As a part-time, remote contractor, you'll test and guide AI models through hands-on prompts and analysis.
Mercor
VerifiedCybersecurity SWE — AI Safety | $60-$90/hr Remote
This part-time remote role invites a cybersecurity engineer to apply their skills in AI safety — no prior machine learning background needed. You'll work hands-on evaluating how advanced AI models handle sensitive security topics, with full training on the workflow. It's a unique chance to blend deep security knowledge with the frontier of AI development.
Mercor
VerifiedCybersecurity / IT GRC Evaluator | $80-$120/hr Remote
We're seeking seasoned professionals in Cybersecurity and IT GRC to evaluate AI-generated work products like documents, spreadsheets, and slide decks. In this remote, hourly role, you'll apply your subject-matter expertise to grade outputs for accuracy, rigor, and domain quality. It's a chance to shape the quality of AI tools by providing expert feedback.
Micro1
VerifiedRed Team Lead (Offensive Cybersecurity) | $50-$90/hr Remote
This remote contractor role with micro1 puts your offensive cybersecurity expertise to work in a unique way: you'll help train next-generation AI systems by designing evaluation frameworks and attack simulations. No prior AI experience is required—your hands-on knowledge of exploit chains, cloud/appsec, and social engineering is what makes you the ideal candidate. You'll shape how models learn about real-world threats while operating under strict ethical boundaries.