Logo for Mercor

Security Review Expert - SOC 2

Role overview

Qualifications

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM)
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
  • Strong written communication skills; comfortable producing structured, rubric-style feedback
  • Relevant security certification, such as CISSP or CISA

Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal
  • Assess data-handling and sub-processor risk for vendors touching sensitive data

About the company

Mercor logo

Mercor

Job Boards & Talent Marketplaces

Company details

IndustryJob Boards & Talent Marketplaces

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Security Expert
Type: Contract
Compensation: $90–$110/hour
Location: Remote

Role Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
  • Assess data-handling and sub-processor risk for vendors touching sensitive data.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
  • Strong written communication skills; comfortable producing structured, rubric-style feedback.

Preferred

  • Relevant security certification, such as CISSP or CISA.
  • Prior task-writing, rubric-authoring, or AI-training data experience.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Mercor

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.