Work Expert (WE) is an independent publishing and referral website. We are not a recruiter, hiring manager, agent or employer, and we are not affiliated with or endorsed by Mercor. Applying takes you to the platform's own website, where we may be recorded as the referring source. We may receive a referral fee at no additional cost to you. Read our full affiliate disclosure →
About the Role
Mercor is building realistic, high-fidelity simulated environments to evaluate and train AI models on real-world procurement workflows for a leading spend-management technology company. We're looking for security and vendor-risk professionals to author and validate security-review tasks inside these simulated environments. Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard
What You'll Do
Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard
Catch scope mismatches and lapsed bridge letters that a surface-level review would miss
Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal
Assess data-handling and sub-processor risk for vendors touching sensitive data
You're a Good Fit If You
8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM)
Independent contractor engagement, fully remote. Mercor pays weekly via Stripe or Wise.
Common Questions
Mercor has a reliability rating of very reliable based on the listings we track, with an onboarding time of 1-3 weeks (interview + assessment + trial). See our full Mercor review for the details behind that rating.
Applying takes you to Mercor's own website, where the application is completed. We are not a recruiter or employer and do not process applications directly - we may be recorded as the referring source.
$90-$110/h - Independent contractor engagement, fully remote. Mercor pays weekly via Stripe or Wise.
Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard Catch scope mismatches and lapsed bridge letters that a surface-level review would miss Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal