ForgeApply · Job listing
Security Engineer, Cloud Infrastructure
Mercor
See all 81 open roles at Mercor →
Tailor your resume for this Mercor job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Mercor's site with it. You review everything before it's sent. Free trial, no card required.
About this role
ABOUT MERCOR
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll own cloud and infrastructure security at a company where tenant isolation is a critical enterprise requirement. Mercor's customers - including frontier AI labs - need hard guarantees that their data stays within strict boundaries. This is not a compliance checkbox role. You'll architect multi-account AWS isolation, harden Kubernetes clusters, deploy cloud security posture management, and build the infrastructure that lets Mercor serve enterprise clients who demand the highest security bar.
We use AI heavily in our own security work. You should be comfortable building alongside AI code-gen tools, using LLMs to accelerate infrastructure review and policy authoring, and automating away the repetitive work that slows infrastructure security down. If you'd rather write a Terraform module than fill out a spreadsheet, you'll fit in here.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
WHAT YOU'LL BUILD:
- Multi-account AWS tenant isolation architecture - dedicated accounts, SCPs, network boundaries, and data segregation for enterprise clients
- Cloud security posture management using Wiz CSPM - continuous monitoring, misconfiguration detection, and automated remediation
- Kubernetes security hardening - pod security standards, network policies, secrets management, and runtime protection
- Infrastructure-as-code security guardrails - Terraform/CloudFormation policies that prevent insecure deployments before they reach production
- IAM architecture and least-privilege access controls across AWS, Snowflake, and internal services
- Incident response infrastructure - logging pipelines, forensic readiness, and blast radius containment
WHAT WE'RE LOOKING FOR
- Deep AWS security expertise - you've architected multi-account strategies, written SCPs, and hardened production environments
- Experience with Kubernetes security in production - not just tutorials, you've secured real clusters running real workloads
- Strong infrastructure-as-code skills - Terraform, CloudFormation, or Pulumi - you think in code, not console clicks
- Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar) - deploying, tuning, and driving remediation
- Understanding of network security at the cloud level - VPCs, security groups, transit gateways, PrivateLink
- You've designed tenant isolation for multi-tenant SaaS - data segregation, compute isolation, network boundaries
- 5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus
BONUS POINTS
- Experience with Snowflake security - schema-level isolation, access controls, data sharing governance
- Familiarity with container runtime security (Falco, SentinelOne Cloud Workload Protection, or similar)
- Offensive cloud security skills - you've exploited misconfigurations and understand the attacker's perspective
- Experience building compliance-ready infrastructure (SOC 2, ISO 27001, FedRAMP)
- You've handled cloud security incidents - forensics, containment, and root cause analysis in AWS
- Contributions to open source infrastructure security tools
WHY MERCOR
- The deliverable is concrete. Enterprise clients require tenant isolation as a baseline. You'll build infrastructure that directly enables the business.
- AI-native infrastructure security. You'll use frontier AI tools daily - for policy authoring, misconfiguration analysis, and anything that benefits from an AI co-pilot.
- Ownership from day one. You'll own the entire cloud security domain - from AWS architecture to Kubernetes hardening to CSPM operations.
- See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market.
Benefits
- Bi-annual performance bonus structure
- Generous equity grant vested over 4 years
- Up to $15k Relocation bonus
- $10K housing bonus (if you live within 0.5 miles of our office)
- $1.5K monthly stipend for meals
- Free Equinox membership
- $200 monthly laundry reimbursement
- $200 monthly personal wellness reimbursement
- Health, Dental, Vision insurance
Salary insight
The midpoint of this range ($265k) is about 33% above the median disclosed salary for San Francisco roles listed on ForgeApply ($200k across 8,787 jobs).
See full Security Engineer salary data for San Francisco →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Mercor role before you apply.
Tailor my resume for this jobSimilar jobs
- Security Engineer, Cloud — Ramp · New York, NY (HQ)
- Security Engineer, Cloud — Vercel · Remote
- Security Engineer, Infrastructure — Fluidstack · New York, NY
- Security Engineer, Infrastructure — Serval · San Francisco
- Security Engineer, Infrastructure — Scaleai · New York, NY; San Francisco, CA; Seattle, WA; Washington, DC
- Security Engineer, Infrastructure Security — Openai · Remote
- Security Engineer - Cloud and Network Security — Gusto · San Francisco, CA - Hybrid
- Software Engineer, Cloud Infrastructure — Gleanwork · San Francisco, CA
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in San Francisco · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)