Job Title: AI Response Evaluator for Cyber Security Threat Intelligence Location: Remote Job Type: Task-Based Contract (Make your own hours: 5 hours per week minimum) Overview: We are seeking a highly skilled and motivated individual to join our team as an AI Response Evaluator…
Security Expert
Job description
Role Overview
Mercor is seeking an experienced Security Expert to help train next-generation AI systems by contributing real-world security review and third-party risk management expertise. In this fully remote hourly contract role, you will evaluate simulated vendor security reviews, validate compliance evidence, and create structured evaluation rubrics that teach AI how experienced security professionals assess vendor risk.
This opportunity is ideal for senior professionals with extensive experience in security reviews, vendor risk management, and third-party risk assessments.
Key Responsibilities
Evaluate Vendor Security Reviews
- Review simulated vendor security documentation, including SOC 2 reports, security questionnaires, penetration testing reports, and compliance evidence.
- Compare submitted security documentation against buyer security requirements.
Assess Security & Vendor Risk
- Identify scope mismatches and expired bridge letters that may be overlooked during basic reviews.
- Evaluate vendor data handling practices and sub-processor risks.
- Assess security posture for vendors processing sensitive information.
Create AI Training Content
- Develop detailed evaluation rubrics reflecting real-world security review processes.
- Author high-quality reference ("golden") responses for AI training.
- Document the reasoning behind security approval and renewal decisions.
Validate Simulated Environments
- Review simulated security review environments for realism and consistency.
- Identify contradictions or unrealistic scenarios before evaluation tasks are released.
- Help improve AI reasoning across security review and third-party risk workflows.
Required Qualifications
- 8+ years of professional experience in security review, vendor risk management, and third-party risk management (TPRM).
- Hands-on experience evaluating SOC 2 reports, security questionnaires, compliance documentation, and security assessment evidence.
- Strong written communication skills and the ability to produce structured, rubric-based evaluations.
Preferred Qualifications
- Professional security certifications such as CISSP or CISA.
- Experience with AI training, task authoring, and rubric development.
Compensation
- $90 to $110 per hour
- Weekly payments via Stripe or Wise
Work Arrangement
- Fully remote
- Independent contractor
- Flexible schedule
- Project-based engagement with potential extensions based on business needs and performance
You will be redirected to the company's website to complete your application.