All four generalists already recruit security experts. Only one of them matters, and the reason is not its rates.
The rate table, reconciled
Four research files quote Mercor cyber rates and they do not agree, because they were reading different postings. Reconciled, with the file each figure comes from and whether it is a live Mercor-controlled listing or a secondary source:
| Role | Rate | From | Live posting? |
|---|---|---|---|
| Mercor — Cybersecurity Research Expert, Offensive Security & Vulnerability Research | $200–250/hr | sec-legal | Live (Mercor) |
| Mercor — Cybersecurity Labeling Expert | $100–150/hr, "Worldwide Remote" | sec-legal | Secondary (benture.io) |
| Mercor — Cyber Security Experts (blue team, SIEM/EDR) | $85–95/hr | sec-defensive, sec-legal | Live (Mercor) |
| Mercor — Cybersecurity Expert (scenario + rubric authoring) | $80–90/hr | sec-product, sec-legal | Live (Mercor) |
| Mercor — Cybersecurity Experts (vulnerability pattern recognition) | $70–90/hr | sec-offensive | Live (Mercor) |
| Mercor — AI Red-Teamer, Adversarial AI Testing | $54–111/hr | sec-product | Live (Mercor) |
| Mercor — Cybersecurity SWE, AI Safety | $60–90/hr, 15–25 h/wk | sec-defensive (now closed), sec-product | Live at time of capture |
| Mercor — Penetration Tester | $1,750–2,150 per completed task | sec-product | Secondary (Himalayas) |
| Mercor — published bands, all domains | expert/specialist $75–200+/hr; national average $31/hr | sec-product | Live (Mercor) |
| Handshake AI — Fellowship Security Engineer | up to $80/hr, part-time, no minimum hours | sec-product | Live (Handshake) |
| OpenTrain — AI red-team roles (aggregated) | $40–62/hr; QA lead to $100/hr | sec-defensive | Secondary (OpenTrain) |
The clearing range for security expert-data labour is $54–250/hr, with offensive and vulnerability research at the top, blue-team incident reasoning in the middle, and scenario and rubric authoring at the bottom. Not $70–90. Not $85–95. Those are two rungs of a ladder that has at least six.
sec-offensive and sec-product both conclude that Mercor's cyber work "does not reach the exploit-development tier" and that credentialed offensive labour is Mercor's structural weakness. That conclusion was drawn against the $80–90/hr scenario-authoring posting. sec-legal then found a live Mercor posting at $200–250/hr explicitly titled "Offensive Security & Vulnerability Research", seeking top-ranked CTF team members, CVE discoverers, publicly recognised bug bounty researchers and published security researchers, with OSCP/OSEP/OSCE3/GIAC preferred.
Mercor is already recruiting the exploit-development tier, at a rate no other generalist approaches. The "they cannot reach that supply" argument is weaker than the earlier files assumed and should not be leaned on.
The gap that does survive is narrower and worth stating precisely. Mercor's Cybersecurity Expert brief asks for CISSP/CISM holders with 5+ years to author scenarios, reference outputs and rubrics against NIST CSF, SOC 2, ISO 27001 and EU NIS2 — that is compliance- and GRC-flavoured content. The offensive posting exists, but the volume posting is governance work. What no generalist demonstrably operates is the infrastructure around the labour: multi-host bare-metal ranges, a reproduction-capable triage panel of the kind Anthropic buys from six external firms, or a contamination-protected private evaluation set. See Irregular, in full for what that infrastructure looks like when someone does run it.
sec-offensive records the Mercor cyber role as geo-restricted to US/CA/UK/AU/NZ with enhanced background screening. sec-legal checked the Mercor-controlled pages directly and found "fully remote globally" and "Worldwide Remote," with an H-1B/STEM-OPT note as the only restriction and no background check mentioned on any posting read. One aggregator lists a Five-Eyes restriction on a page that 404'd. Treat the restriction as unconfirmed.
The other three
Handshake AI is the closest direct competitor to a specialist's likely first product. Its AI Red Teamer, Cybersecurity role demands professional offensive-security, malware-analysis, threat-intel or IR experience, evaluating "whether models provide meaningful uplift across the cyber kill chain" and building "structured harm taxonomies and severity rubrics calibrated to real-world exploitability" (Handshake/Ashby). Severity rubrics calibrated to exploitability is precisely the logic-bug oracle problem — the artefact with no automated verifier, which is where the durable margin sits. Its structural weakness is reputational: contractors on OpenAI projects publicly alleged Handshake withheld thousands of dollars in pay (Business Insider, March 2026), which matters disproportionately in a small, reputationally networked expert community.
Surge AI: roughly $1.2B revenue (2024, per TechCrunch), bootstrapped, 51–200 staff. No cyber-specific product or public cyber rate could be found — the careers page and job board surfaced no security-vertical roles. Surge's pattern is to compete on quality and margin without press, so the likely counter-move is a quiet vertical hire nobody announces.
Scale AI: $1.6B raised, SOC 2 Type II, Meta's $14B investment, a public-sector evaluation offering, and no cyber-specific data or environment product that could be established. Post-Meta, several labs reduced reliance, which makes an aggressive frontier-lab cyber push less likely than a government-facing one.
The counter-move is acquisition, not competition
This is the part that should govern the plan, and it is well evidenced.
Mercor is running at a $2B annualised gross revenue run rate as of June 2026, up 100% in four months, with H1 2026 revenue over $615M and ~90% of it from OpenAI and other giants (SiliconANGLE). Gross, every time — that is money passing through to contractors, not money Mercor keeps, and the distinction is the reason GMV is not revenue exists. Ninety percent of revenue from a handful of labs is also the single sharpest One customer is a binary event figure in the atlas.
And Mercor buys environments rather than building them. Two acquisitions in five months: Sepal AI in February 2026 and Deeptune in July 2026 — Deeptune having raised a $43M Series A in March 2026, four months before it was acquired, having "recreated hundreds of enterprise applications over two years" and built "hundreds of virtual training gyms" for leading labs (SiliconANGLE).
A company that raised a $43M Series A in March was acquired in July. That is the live comparable for what a demonstrated environment business with lab logos is worth to Mercor, and it is the base case rather than the upside case: if you demonstrate a cyber environment product with frontier-lab references, the expected outcome is an acquisition offer, not a competitive build. Mercor has done it twice in five months, both times for environments, against a gross run rate that makes either deal a rounding error.
That reframes the entry decision. The question is not "can we out-execute Mercor on cyber data" — with 90% of revenue from labs and a $2B gross run rate, Mercor does not need to win cyber, it needs to not lose it, and buying is faster. The question is what the acquirer would be buying, and the answer had better not be a rate card. Rates are visible, copyable and already published. What is not copyable quickly is the credentialed offensive supply at the exploit-development tier, an operated infrastructure with an incident-response posture, and the standing to hold a private evaluation set — the three things Irregular, in full has and no marketplace does.
The other thing the generalists can do immediately is undercut on the commoditised tier, where Bugcrowd's hundreds of thousands of memory-safety environments already set the floor at effectively zero marginal cost. Do not plan to sell those. And note what none of the four generalists has: a citation in a frontier system card, which is the asset Gray Swan, in full and Irregular, in full were both valued on, and the one thing money cannot buy directly. Offensive security and The defensive vendors carry the rest of the field.
Surge's and Scale's cyber-specific products and rates — absent from every public source checked. Whether Mercor's $200–250/hr offensive posting is filling, or is an aspirational listing that has been open for months. Mercor's take rate on any cyber engagement, which would convert the gross figure into something comparable. And the identity of the unnamed "cutting-edge AI research lab" behind the $85–95/hr blue-team listing, which is a named, currently-paying buyer for exactly this work.