Vercel's security team is looking for a Product Security Engineer to drive critical product security initiatives — threat modeling, open-source security, secure code review, SDLC tooling, and bug bounty program management — across the platform.
Responsibilities
- ▹Perform threat modeling and design review together with engineering and product teams for new and existing features
- ▹Conduct secure code reviews and security assessments on products built with Next.js, Node.js, and serverless backends
- ▹Oversee open-source security: coordinate fixes for vulnerabilities in third-party packages and maintain security of Vercel's own open-source projects (e.g. Next.js)
- ▹Evaluate, select, and integrate security tools into the SDLC (e.g. GitHub Advanced Security, SAST, dependency scanning, secret detection) within CI/CD pipelines
- ▹Own and expand the bug bounty program: triage and validate reports, coordinate remediation, and refine policy and scope
- ▹Lead cross-organizational security initiatives and act as a security champion across engineering
- ▹Support customer-facing security efforts: documentation, questionnaires, audits, and communicating security features
Requirements
- ▹5+ years of experience in product security or a related role, securing web products and services
- ▹Strong JavaScript/TypeScript and Node.js runtime security knowledge, familiarity with modern web frameworks (Next.js, React) and their security considerations
- ▹Demonstrated threat modeling and architectural risk analysis experience, integrating security into a fast-paced SDLC
- ▹Hands-on experience with SAST/DAST tools, dependency vulnerability scanners, and CI/CD security integration
- ▹Open-source and supply chain security knowledge (e.g. Dependabot, Snyk)
- ▹Exposure to running or participating in a bug bounty or vulnerability disclosure process, up-to-date with OWASP Top 10
- ▹Solid understanding of cloud and serverless security
- ▹Proven ability to drive security initiatives and influence engineering teams
Nice to have
- ▹Prior software development experience beyond security (frontend or backend)
- ▹Relevant certifications: OSCP, OSWE, CISSP, or notable bug bounty recognitions
- ▹Experience with policy-as-code or infrastructure-as-code security (e.g. Open Policy Agent, Terraform security checks)
- ▹Built security features (authentication, encryption, secure CI/CD) or contributed to security community projects
Soft skills
Cross-organizational leadership and influenceClear, effective communicationFostering a security-first culture across engineering
About the company
Vercel is the agentic infrastructure company, the team behind Next.js, v0, and the AI SDK, trusted by companies like OpenAI, PayPal, Ramp, and Supreme, and millions of developers worldwide.
Languages: Angol: Felsőfok
Ähnliche Stellen

Stelle
Infrastructure Security Engineer, Public Sector
Scale AI
Cloudformation
+5
170 350–293 648 €/Jahr
brutto
🏢 Vor Ort
St. Louis
🗣️ EN

Stelle
Product Security Engineer, Public Sector
Scale AI
+1
170 350–293 648 €/Jahr
brutto
🏢 Vor Ort
St. Louis
🗣️ EN

Stelle
Security Engineer, Product Security
Scale AI
AI/ML
+3
204 008–255 010 €/Jahr
brutto
🏢 Vor Ort
San Francisco
🗣️ EN

Stelle
Cloud Security Engineer
Hex
+7
171 724–227 534 €/Jahr
brutto
🏢 Vor Ort
US Timezones
🗣️ EN

Stelle
Product Security Engineer II
Affirm
+1
141 672–193 189 €/Jahr
brutto
🌍 Remote
🗣️ EN

Stelle
Security Engineer, Platform
Resend
8 586–10 046 €/Mon.
brutto
🌍 Remote
🗣️ EN
