3 months ago
Base Salary
$208k - $312k/yr
Responsibilities
- Perform threat modeling and architectural security reviews for new and existing product features.
- Conduct secure code reviews and security assessments for products and services built with Next.js, Node.js, and serverless backends.
- Manage security for third-party open-source dependencies and open-source projects maintained or published by Vercel, including responsible disclosure and patching.
- Evaluate, select, and integrate security tooling into the software development lifecycle, CI/CD pipelines, and GitHub workflows.
- Own and expand Vercel’s bug bounty program by triaging reports, validating vulnerabilities, coordinating remediation, and refining program policies and scope.
- Lead cross-organizational security initiatives such as framework upgrades, authentication and authorization improvements, and security awareness programs.
- Support customer-facing security initiatives, documentation, whitepapers, security questionnaires, audits, and communication of security features and practices.
Requirements
- At least 5 years of experience in product security or a related field securing web products and services.
- Strong familiarity with JavaScript, TypeScript, Node.js runtime security, and modern web frameworks such as Next.js or React.
- Demonstrated experience with threat modeling, architectural risk analysis, secure design, code review, and penetration testing within a secure development lifecycle.
- Hands-on experience with SAST, DAST, dependency vulnerability scanners, and CI/CD pipeline security integration.
- Knowledge of open-source security, dependency and package-management security, and tools such as Dependabot or Snyk.
- Experience running or participating in bug bounty or vulnerability disclosure programs, including reproducing, validating, and coordinating remediation of vulnerabilities.
- Understanding of OWASP Top 10, emerging threats, cloud architecture, serverless environments, APIs, secrets, and key management.
- Ability to lead cross-functional security initiatives and influence engineering teams.
- Security certifications or recognitions such as OSCP, OSWE, CISSP, or bug bounty hall-of-fame entries are preferred but not required.
- Experience with open-source contribution or maintenance, prior software development, policy-as-code, infrastructure-as-code security, product security features, or security community participation is preferred.
Benefits
- Inclusive healthcare package.
- Mentorship and opportunities to attend events for professional growth and networking.
- Flexible time off.
- Company-provided equipment and a work-from-home budget.
- Fully remote work for employees outside the predetermined commuting distance of SF, NY, London, or Berlin offices; otherwise in-office anchor days are Monday, Tuesday, and Friday.
Tech Stack
Categories
About Vercel
Vercel builds a frontend cloud platform for developing, previewing, and deploying web applications, with strong support for React and Next.js. It sells usage-based and enterprise plans to developers and companies, and it stewards the open-source Next.js framework alongside tools like the AI SDK. Founded in 2015 and headquartered in San Francisco, the privately held company focuses on speeding up modern web development and delivery.
