PitchMeAI
Mercor

Security Analyst - Fully Remote

Mercor · United States

  • Hybrid
  • Part-time
  • $24,500 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Evaluate AI outputs in cybersecurity.
  • Create realistic security scenarios.
  • Annotate and validate cybersecurity data.
  • Provide feedback on AI accuracy.
  • Collaborate on cybersecurity AI frameworks.

About the role

About The Job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Cybersecurity Expert

Type: Contract Compensation: $1,750–$2,150 per completed task Location: Remote

Role Responsibilities

  • Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations.
  • Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat hunting queries, and penetration testing reports.
  • Annotate, label, and validate data across cybersecurity use cases like CVE classification accuracy and SIEM alert triage.
  • Provide structured feedback on AI accuracy in areas such as cybersecurity frameworks (NIST CSF, MITRE ATT&CK) and threat intelligence standards (STIX/TAXII).
  • Collaborate asynchronously with research teams to refine evaluation frameworks for cybersecurity AI.

Qualifications

Must-Have
  • 3+ years of professional experience in cybersecurity at an enterprise organization, MSSP, consultancy, or government/defense environment.
  • Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat intelligence, or security architecture.
  • Strong analytical thinking and ability to translate security operations into structured evaluation tasks.
  • Clear written communication and attention to detail.
Preferred
  • Professional certifications like CISSP, CISM, CEH, OSCP, GIAC certifications, Security+.

Compensation & Legal

Task Completion Pay: Competitive and based on task quality. Performance Bonus: Weekly bonus incentive for top performers. Hourly Opportunity: Transition to hourly compensation for sustained quality.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome For any help or support, reach out to: support@mercor.com PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Key skills/competency

  • Cybersecurity Expert
  • Threat Analysis
  • Vulnerability Assessment
  • Security Architecture
  • Incident Response
  • Penetration Testing
  • Threat Intelligence
  • NIST CSF
  • MITRE ATT&CK
  • STIX/TAXII

Skills & topics

  • Cybersecurity Expert
  • Remote
  • AI
  • Threat Analysis
  • Vulnerability Assessment
  • Security Architecture
  • Incident Response
  • Penetration Testing
  • Threat Intelligence
  • NIST CSF
  • MITRE ATT&CK
  • STIX/TAXII
  • CISSP
  • CISM
  • CEH
  • OSCP
  • GIAC
  • Security+

How to get hired

  • Tailor your resume: Highlight 3+ years of cybersecurity experience, SOC analysis, incident response, or threat intelligence.
  • Prepare for AI interview: Be ready to discuss your resume and cybersecurity expertise.
  • Understand the task pay: Note the compensation structure and potential for bonuses.
  • Review resources: Familiarize yourself with the interview process via the provided link.

Technical preparation

Review cybersecurity frameworks (NIST, MITRE).,Practice creating security scenarios.,Familiarize with STIX/TAXII standards.,Understand AI evaluation methods.

Behavioral questions

Describe your experience with AI in cybersecurity.,How do you provide constructive feedback?,Explain your incident response process.,How do you handle detailed data annotation?

Frequently asked questions

What is the compensation for the Cybersecurity Expert role at Mercor?
The Cybersecurity Expert role at Mercor is compensated on a per-task basis, ranging from $1,750 to $2,150 per completed task. There are also opportunities for weekly performance bonuses for top performers, and a potential transition to hourly compensation for sustained high quality.
Is the Cybersecurity Expert position at Mercor remote?
Yes, the Cybersecurity Expert position at Mercor is fully remote, offering flexibility in where you work.
What is the expected time commitment for the application process for Mercor?
The application process for Mercor, including uploading your resume and completing the AI interview, is estimated to take approximately 20–30 minutes.
What specific cybersecurity areas are most relevant for the Mercor Cybersecurity Expert role?
Mercor is seeking candidates with experience in SOC analysis, incident response (DFIR), penetration testing, threat intelligence, or security architecture. A strong background in evaluating AI outputs related to threat analysis, vulnerability assessment, and security recommendations is key.
Does Mercor require specific certifications for the Cybersecurity Expert role?
While not strictly required, Mercor prefers candidates with professional cybersecurity certifications such as CISSP, CISM, CEH, OSCP, GIAC certifications, or Security+. These can strengthen your application.
How are candidates evaluated for the Cybersecurity Expert role at Mercor?
Candidates are evaluated based on their professional experience in cybersecurity, analytical thinking, communication skills, and their ability to translate security operations into structured evaluation tasks. The application includes an AI interview based on the resume.
What kind of feedback is expected from the Cybersecurity Expert at Mercor?
The Cybersecurity Expert is expected to provide structured feedback on AI accuracy, particularly concerning cybersecurity frameworks like NIST CSF and MITRE ATT&CK, and threat intelligence standards like STIX/TAXII. This includes annotating, labeling, and validating data.