Mercury Insurance Services, LLCremote

Salary
$128,136–$252,194from the description
Posted
Jun 30, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual contributor role within an insurance company's information security team, responsible for designing and enforcing security architecture across IT and business initiatives, with a focus on application security, penetration testing, threat analysis, and incident response. The position also involves consulting on security standards for enterprise projects and guiding other members of the security organization. It suits a deeply experienced security professional with at least 12 years in the field and a background spanning architecture, vulnerability assessment, and leadership.

Principal level · 18+ years · Remote · Full-time

Advertised as Senior, but the requirements read as Principal.

Must have (17)
application securitypenetration testingOWASPincident responsevulnerability assessmentnetwork vulnerability testingJava.NETencryptionaccess controlintrusion detectionfirewallUNIXWindowsTCP/IPDNSPCI DSS
Nice to have (3)
CISSPSANS certificationsCISA

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 280 people nationally plausibly meet what this posting asks for (information security analysts). range 60–420

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
UNIX65%incident response62%firewall48%vulnerability assessment45%application security40%TCP/IP40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The posting requires 18–20 years of total IT experience with at least 12 years directly in Information Security. This scope — combined with org-wide security architecture authority, incident command leadership, and enterprise policy/standards ownership — supports a Principal-level classification despite the 'Senior' title.

The Bachelor's degree requirement is stated as 'or equivalent professional experience,' so no minimum degree is hard-gated.

CISSP, SANS certifications, and CISA are listed under 'Preferred' and described as 'highly desirable' or 'desirable,' so they are not hard gates.

Java and .NET appear under the required Knowledge and Skills section in the context of 'detailed knowledge of web application development,' making them hard gates on familiarity with those platforms for application security purposes.

Compensation ranges vary by state; the pay range field reflects the highest-tier range (NJ/NY/WA/HI/AK/MD/CT/RI/MA: $128,136–$252,194) as that is also the figure quoted in the posting's Pay Range field. The CA range ($171,148.50–$237,706.25) and lower-tier state ranges are noted here for completeness.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): threat analysis.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗