Role Overview
Mercor is seeking senior cybersecurity professionals to build evaluation tasks for AI systems operating in security operations, incident response, and risk management contexts.
The workflows are calibrated to the threat sophistication, business risk stakes, and scope of major enterprise security programs.
This role builds worlds on two tracks: a US track (NIST Cybersecurity Framework, SOC 2) and an International track (ISO 27001, EU NIS2 Directive). Experts qualified in either or both tracks are encouraged to apply.
Contributors design cybersecurity scenarios, draft reference outputs, and write rubrics that capture how senior security leaders think.
Key Responsibilities
Construct cybersecurity scenarios spanning security operations center monitoring, incident response and forensics, vulnerability management, and security architecture design.
Build tasks across security operations and threat detection, incident response and digital forensics, vulnerability and penetration testing, security architecture and engineering, and governance/risk/compliance.
Develop scenarios involving tools such as SIEM platforms (Splunk, Microsoft Sentinel), EDR tools (CrowdStrike), vulnerability scanners (Tenable, Qualys), and GRC platforms used at major enterprises.
Apply cybersecurity methodologies (threat modeling, incident response playbooks, risk assessment) to the standards track a world targets (US: NIST CSF, SOC 2; International: ISO 27001, NIS2), and produce reference incident reports, security assessments, architecture designs, and compliance documentation.
Author rubrics that distinguish authentic security judgment from generic textbook or certification-exam-level recall.
Ideal Qualifications
5+ years working as a security engineer or CISO at a major company or security firm (Mandiant, CrowdStrike, or an in-house CISO/security lead).
Direct ownership of incident response programs, security architecture, or compliance initiatives.
Fluency in security tooling, plus understanding of regulatory frameworks and the current threat landscape.
A recognized professional credential is strongly preferred (CISSP, CISM, or an international equivalent); prior rubric or training authorship is a plus.
New
New