Security Review Expert - SOC 2
Offre en anglaisThe role involves reviewing simulated vendor SOC 2 reports and security questionnaires against buyer standards to identify scope mismatches. The expert will also author step-level rubrics and assess data-handling risks to improve AI model performance.
- Télétravail
- Montreal, Quebec, Canada
- Publié 6 août 2026
- Postuler avant le 5 sept. 2026
- 1 poste
Résumé du poste
About The Job Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Security Expert Type: Contract Compensation: $90–$110/hour Location: Remote Role Responsibilities Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard. Catch scope mismatches and lapsed bridge letters that a surface-level review would miss. Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal. Assess data-handling and sub-processor risk for vendors touching sensitive data. Work independently and asynchronously to meet deadlines while improving AI model performance. Qualifications Must-Have 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM). Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence. Strong written communication skills; comfortable producing structured, rubric-style feedback. Preferred Relevant security certification, such as CISSP or CISA. Prior task-writing, rubric-authoring, or AI-training data experience. Application Process (Takes 20–30 mins to complete) Upload resume AI interview based on your resume Submit form Resources & Support For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome For any help or support, reach out to: support@mercor.com PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity. ,
Ce que vous ferez
The role involves reviewing simulated vendor SOC 2 reports and security questionnaires against buyer standards to identify scope mismatches. The expert will also author step-level rubrics and assess data-handling risks to improve AI model performance.
Exigences
Candidates must have over 8 years of professional experience in security review or TPRM and hands-on experience with SOC 2 reports. Preferred qualifications include CISSP or CISA certifications and experience in rubric-authoring or AI training.
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Security Review
- Vendor Risk Management
- Third-Party Risk Management
- SOC 2 Report Evaluation
- Compliance Evidence Review
- Rubric Authoring
- Data-Handling Assessment
- Sub-processor Risk Assessment
- Written Communication
- AI Training Data Experience
Domaines d’emploi
- Security & Safety
- Technology
- Software
- Consulting
- Data & Analytics
Renseignements supplémentaires
- Formation minimale
- Diplôme professionnel
- Expérience minimale
- 10+ ans
- Postuler avant le
- 5 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Exigences de lieu
- Country, Greater Montreal Metropolitan Area
- Niveau d’expérience
- Not Applicable