Application Security Engineer (AppSec)
- Pay
- $30 – $100 / Hour
- Open to
- Worldwide
- Apply
We earn a commission if you sign up through the links on this page. It costs you nothing and does not affect which jobs we list. How this works.
- Skills
- python3
- java
- rust
- typescript
- pentesting
- security audit
- bug fixing
What you'll do
The title says AppSec, but the core deliverable is task authoring. You write realistic, non-trivial coding challenges for an AI model (implement this feature, fix this bug) and then write the verifier that grades its answer. The verifier has to be deterministic, accept any reasonable correct solution, and reject everything else.
That last clause is where security experience earns its keep. A verifier is an attack surface: a model under training will happily find the shortcut that passes the checks without doing the work. Someone used to thinking about how input validation fails, or how a test can be gamed, writes better verifiers. The ad calls a security background "a big plus" rather than a requirement.
Who fits
- Strong backend experience in Java, Node.js, Go, Rust, TypeScript, Python, C++ or similar
- A record of building scalable services and APIs
- Comfort with debugging, performance work and automated testing
- Good code review instincts
- Preferred: secure coding, application security, pentesting, vulnerability assessment, OWASP/CWE familiarity or security-focused code review
The ad asks you to complete the interview and assessment without outside help, and to bring the same independence to the project itself.
What it pays
The band is $30–100/hour, but pay is output-based: per task that meets specification, with a weekly minimum number of tasks whose value the ad leaves blank. The spread is wide, and the effective rate will track how quickly you can produce tasks and verifiers that pass review.
How you get hired
Screening questions, a roughly 30-minute AI interview, a technical assessment (marked tentative), and a hiring manager review. Roles typically fill within 48 hours, with first tasks expected 24 to 48 hours after onboarding.
Worth knowing
Good:
- 300 openings, recently posted and marked high demand
- Choose your own hours, weekends included, at around 15 hours a week
- Security skills are rewarded without being mandatory
Less good:
- A $30 floor and a 3x spread, paid per accepted task
- Weekly minimum stated but not quantified
- Little of the work is actual security testing; it is mostly task and test writing
- Contractor engagement: no benefits, no notice period, your own tax to manage
About this listing
Posted by micro1 on its own jobs portal a few days before we read it on 24 September 2026. micro1 runs the same ad text under the title Backend Security Engineer; we list it once. A related Cyber Security Engineer posting on the same band describes more hands-on audit and pentest work. Location is "Remote" with no country named. See micro1.
More roles at micro1
See all 380Similar roles at other platforms
- Application Users - Android Studio on macOS - CodeMercor · $55 – $65 / Hour · 16d ago
- Application Users - macOS Sonoma 14.5 Expert - ProfessionalsMercor · $60 – $70 / Hour · 16d ago
- Senior Software Engineer: AI Evaluation & BenchmarksAlignerr · $80 – $100 / Hour · 1mo ago
- Real-world terminal and infrastructure scenariosInvisible Technologies · $35 / Hour · 15d ago
Guides about micro1
See all 81- micro1 Computer Vision Engineer Interview: Transfer Learning, Preprocessing and DetectionInterview prep
- micro1 Data Engineer Interview: ETL Reliability, Data Quality and Warehouse CostInterview prep
- micro1 AI Engineer Interview: Feature Engineering, Overfitting and Deploying ModelsInterview prep
- micro1 DevOps Engineer Interview: Continuous Integration, IaC and OrchestrationInterview prep
Browse similar roles
Not the right fit?
See every open role, or get new ones on Telegram or Discord as they are added.