Skip to content
Labeling Jobs

Cybersecurity Practitioner: Paid Expert Interviews (SOC, Incident Response, Detection, AppSec)

Mercor: pay and who it accepts · · Apply link checked

Pay
$125 – $175 / Hour
Open to
  • United States
Apply

We earn a commission if you sign up through the links on this page. It costs you nothing and does not affect which jobs we list. How this works.

Skills
  • security operations
  • incident response
  • digital forensics
  • detection engineering
  • threat hunting
  • application security
  • red teaming
  • siem
  • edr

What you'll do

Talk, mostly. Mercor is building a benchmark to measure how well AI agents handle real enterprise cyber defense work, and before it writes a single task it wants practitioners to describe the job as it actually happens.

The engagement is two to three one-hour video calls with the Mercor team, spread over roughly four weeks and scheduled around you. The conversations cover four areas:

  • Your working day: the tools you live in, what reaches your queue, and which calls need judgment versus which are routine
  • How quality is judged: what makes a triage, investigation, containment, hunt, detection rule or patch "done well" on your team
  • AI in your workflow: where assistance helps today, where it gets in the way, and what would make a benchmark of AI on this work credible to you
  • Their draft task taxonomy: what is missing, what is mislabelled, and what you would weight differently

This is unusual for a Mercor listing. There is no annotation, no rubric scoring, no assessment queue and nothing to build or submit. It is closer to paid user research than to AI training work, and it is short by design.

Who fits

Current or recent hands-on practitioners in enterprise security. The ad names:

  • SOC analysts and SOC leads, tier 2 and above
  • Incident responders and digital forensics investigators
  • Detection engineers and threat hunters
  • Application or product security engineers who find and fix vulnerabilities in production code
  • Security engineers who have run a red team engagement or been on the receiving end of one

Experience with an EDR and SIEM stack (CrowdStrike Falcon, Microsoft Defender and Sentinel, Splunk, SentinelOne, Elastic or similar) is a plus. Security leaders are welcome if they are still close to the work.

Tier 1 alert triage on its own does not appear to qualify; the floor is set at tier 2.

What it pays

$125–175 per hour, Mercor's own published figure. It is paid as a spot bonus for interview time, so the realistic total is two to three hours: roughly $250 at the bottom of the range and $525 at the top. Payments are weekly via Stripe or Wise.

No preparation is expected, so the hourly figure is close to your true effective rate.

Worth knowing

Good:

  • High hourly rate for one-hour conversations with no prep
  • Nothing to label, score or submit, and no assessment hoops described
  • Scheduled around your availability
  • Your input is never attributed to you or your employer

Less good:

  • Small total: at most three sessions, so treat it as a side payment, not income
  • US-based only
  • H-1B and STEM OPT holders are excluded
  • Independent contractor engagement, with the usual "can be extended, shortened, or concluded early" clause
  • Nothing says whether the benchmark work that follows will be offered to interviewees

Confidentiality

You will be asked to describe patterns, not specific incidents, and to leave out anything confidential about current or former employers and customers. If you work under an NDA or in a regulated environment, that framing is what keeps this compatible with your day job: talk about how triage works in general, not about the breach you handled last month.

About this listing

Posted by Mercor as an hourly remote contract for US-based candidates, confirmed open on 24 September 2026. The pay range, session count, eligible roles and payment terms above are the ad's own. No closing date is published. See Mercor.

More roles at Mercor

See all 304

Similar roles at other platforms

Guides about Mercor

See all 52

Browse similar roles

Not the right fit?

See every open role, or get new ones on Telegram or Discord as they are added.