← Zurück zur Liste
Stelle

Product Security Engineer

Security Engineer • Remote • Vollzeit Vereinigte Staaten USA

Vercel's security team is looking for a Product Security Engineer to drive critical product security initiatives — threat modeling, open-source security, secure code review, SDLC tooling, and bug bounty program management — across the platform.

Responsibilities

  • Perform threat modeling and design review together with engineering and product teams for new and existing features
  • Conduct secure code reviews and security assessments on products built with Next.js, Node.js, and serverless backends
  • Oversee open-source security: coordinate fixes for vulnerabilities in third-party packages and maintain security of Vercel's own open-source projects (e.g. Next.js)
  • Evaluate, select, and integrate security tools into the SDLC (e.g. GitHub Advanced Security, SAST, dependency scanning, secret detection) within CI/CD pipelines
  • Own and expand the bug bounty program: triage and validate reports, coordinate remediation, and refine policy and scope
  • Lead cross-organizational security initiatives and act as a security champion across engineering
  • Support customer-facing security efforts: documentation, questionnaires, audits, and communicating security features

Requirements

  • 5+ years of experience in product security or a related role, securing web products and services
  • Strong JavaScript/TypeScript and Node.js runtime security knowledge, familiarity with modern web frameworks (Next.js, React) and their security considerations
  • Demonstrated threat modeling and architectural risk analysis experience, integrating security into a fast-paced SDLC
  • Hands-on experience with SAST/DAST tools, dependency vulnerability scanners, and CI/CD security integration
  • Open-source and supply chain security knowledge (e.g. Dependabot, Snyk)
  • Exposure to running or participating in a bug bounty or vulnerability disclosure process, up-to-date with OWASP Top 10
  • Solid understanding of cloud and serverless security
  • Proven ability to drive security initiatives and influence engineering teams

Nice to have

  • Prior software development experience beyond security (frontend or backend)
  • Relevant certifications: OSCP, OSWE, CISSP, or notable bug bounty recognitions
  • Experience with policy-as-code or infrastructure-as-code security (e.g. Open Policy Agent, Terraform security checks)
  • Built security features (authentication, encryption, secure CI/CD) or contributed to security community projects

Soft skills

Cross-organizational leadership and influenceClear, effective communicationFostering a security-first culture across engineering

About the company

Vercel is the agentic infrastructure company, the team behind Next.js, v0, and the AI SDK, trusted by companies like OpenAI, PayPal, Ramp, and Supreme, and millions of developers worldwide.

Languages: Angol: Felsőfok

Ähnliche Stellen