freehire launches on Product Hunt on 26 August.

Follow →

Security Expert

Summary

Design and validate security-review tasks in AI-powered simulated environments for procurement workflows, evaluating vendor SOC 2 reports and questionnaires against buyer standards.

About the Role

Mercor is building realistic, high-fidelity simulated environments to evaluate and train AI models on real-world procurement workflows for a leading spend-management technology company. We’re looking for security and vendor-risk professionals to author and validate security-review tasks inside these simulated environments.

Key Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer’s security standard

  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss

  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal

  • Assess data-handling and sub-processor risk for vendors touching sensitive data

Ideal Qualifications

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM)

  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence

  • Strong written communication skills; comfortable producing structured, rubric-style feedback

Nice to Have

  • Relevant security certification, such as CISSP or CISA

  • Prior task-writing, rubric-authoring, or AI-training data experience

See also