Senior Security Review and Vendor Risk Architect
Listed on 2026-07-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
About the Role
Mercor is building realistic, high-fidelity simulated environments to evaluate and train AI models on real-world procurement workflows for a leading spend-management technology company. We're looking for security and vendor-risk professionals to author and validate security-review tasks inside these simulated environments.
Key ResponsibilitiesReview simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard
Catch scope mismatches and lapsed bridge letters that a surface-level review would miss
Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal
Assess data-handling and sub-processor risk for vendors touching sensitive data
8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM)
Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence
Strong written communication skills; comfortable producing structured, rubric-style feedback
Relevant security certification, such as CISSP or CISA
Prior task-writing, rubric-authoring, or AI-training data experience
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).