Security Review Expert - SOC 2
Overview
Mercor seeks a Security Review Expert to evaluate vendor SOC 2 reports and security questionnaires. This remote contract role involves analyzing compliance evidence and providing rubric-based feedback. The ideal candidate will improve AI model performance while working independently.
What You'll Do6
- 1Review simulated vendor SOC 2 reports and security questionnaires
- 2Identify scope mismatches and lapsed bridge letters missed by surface-level reviews
- 3Author step-level rubrics and golden responses for request evaluation
- 4Assess data-handling risks for vendors processing sensitive information
- 5Work independently and asynchronously to meet deadlines
- 6Improve AI model performance through security insights
Requirements5
- 18+ years professional experience in security review or TPRM
- 2Hands-on experience evaluating SOC 2 reports and security questionnaires
- 3Strong written communication skills for structured feedback
- 4Preferred certification such as CISSP or CISA
- 5Prior task-writing or AI-training data experience
Salary Insight
$90 - $110k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Mercor
VerifiedSecurity Expert | $90-$110/hr Remote
This is a remote, hourly role for experienced security and vendor-risk professionals to help train AI models on real-world procurement workflows. You'll be authoring and validating security-review tasks inside high-fidelity simulated environments for a leading spend-management company. The work involves reviewing simulated SOC 2 reports, security questionnaires, and penetration-testing evidence, then creating structured rubrics that teach AI how an expert would judge them. It's a chance to put your third-party risk expertise to work in an AI-training context, with competitive pay of $90-$110 per hour.

Mercor
VerifiedCybersecurity Expert | $80-$90/hr Remote
This is a remote, hourly contract role for senior cybersecurity professionals to design evaluation tasks for AI systems used in security operations, incident response, and risk management. You'll create scenarios, reference outputs, and scoring rubrics that capture how top security leaders actually make decisions. The work spans two tracks — a US track based on NIST CSF and SOC 2, and an international track aligned to ISO 27001 and the EU NIS2 Directive — and you can contribute to either or both. It's a unique opportunity to shape how AI is tested for real-world security judgment, with pay at $80–$90 per hour.

Mercor
VerifiedSOC Investigation Specialist Talent Network | $70-$95/hr Remote
Are you a seasoned SOC analyst looking to put your investigative skills to work on next-generation security challenges? Mercor is partnering with high-growth tech and enterprise companies to build AI-driven SOC automation, and we need your real-world expertise to review, validate, and construct high-quality security investigations. In this remote, part-time role, you'll dig into alerts across SIEM, endpoint, cloud, and identity platforms—using Splunk heavily to pivot through logs and reason about SPL queries. Your judgment will directly shape how automated systems and human teams investigate threats, making this a high-impact opportunity for someone who loves the craft of investigation.
Mercor
VerifiedSecurity Operations Expert, AI Trainer & Threat Detection
Security Operations Expert builds realistic cybersecurity scenarios for AI training. You design incident response, vulnerability management, and compliance tasks that distinguish expert judgment from rote recall. Collaborate with a team at Mercor connecting elite talent with AI research labs. Own the challenge from first draft to final rubric, shaping how models learn security thinking.
Actalent
VerifiedSecurity Compliance Analyst Remote
Security Compliance Analyst leads full certification lifecycle for ISO and SOC 2 Type 2 audits, bridging technical engineering teams and external auditors. This fully remote role involves owning end-to-end audit processes, defining technical requirements, and utilizing AI automation to streamline compliance tasks. The ideal candidate is a hands-on practitioner skilled in SaaS environments and capable of articulating technical controls to diverse stakeholders.

Saicon Consultants Inc.
VerifiedCyber Security Analyst - Saicon Consultants Inc.
Lead ownership of GRC Risk Management Analyst duties supporting information security and third-party risk management at a fast-paced environment. This role blends structured governance with hands-on technical expertise to evaluate vendor security postures across the entire relationship lifecycle. You will drive continuous monitoring and offboarding processes while delivering actionable insights that enhance organizational resilience. What sets this position apart is the emphasis on proactive threat scenario modeling and deep architectural analysis.