Vercel

Product Security Engineer

Vercel
Apply
3 months ago
Remote, United StatesSenior
H1B sponsor

Base Salary

$208k - $312k/yr

Responsibilities

  • Perform threat modeling and architectural security reviews for new and existing product features.
  • Conduct secure code reviews and security assessments for products and services built with Next.js, Node.js, and serverless backends.
  • Manage security for third-party open-source dependencies and open-source projects maintained or published by Vercel, including responsible disclosure and patching.
  • Evaluate, select, and integrate security tooling into the software development lifecycle, CI/CD pipelines, and GitHub workflows.
  • Own and expand Vercel’s bug bounty program by triaging reports, validating vulnerabilities, coordinating remediation, and refining program policies and scope.
  • Lead cross-organizational security initiatives such as framework upgrades, authentication and authorization improvements, and security awareness programs.
  • Support customer-facing security initiatives, documentation, whitepapers, security questionnaires, audits, and communication of security features and practices.

Requirements

  • At least 5 years of experience in product security or a related field securing web products and services.
  • Strong familiarity with JavaScript, TypeScript, Node.js runtime security, and modern web frameworks such as Next.js or React.
  • Demonstrated experience with threat modeling, architectural risk analysis, secure design, code review, and penetration testing within a secure development lifecycle.
  • Hands-on experience with SAST, DAST, dependency vulnerability scanners, and CI/CD pipeline security integration.
  • Knowledge of open-source security, dependency and package-management security, and tools such as Dependabot or Snyk.
  • Experience running or participating in bug bounty or vulnerability disclosure programs, including reproducing, validating, and coordinating remediation of vulnerabilities.
  • Understanding of OWASP Top 10, emerging threats, cloud architecture, serverless environments, APIs, secrets, and key management.
  • Ability to lead cross-functional security initiatives and influence engineering teams.
  • Security certifications or recognitions such as OSCP, OSWE, CISSP, or bug bounty hall-of-fame entries are preferred but not required.
  • Experience with open-source contribution or maintenance, prior software development, policy-as-code, infrastructure-as-code security, product security features, or security community participation is preferred.

Benefits

  • Inclusive healthcare package.
  • Mentorship and opportunities to attend events for professional growth and networking.
  • Flexible time off.
  • Company-provided equipment and a work-from-home budget.
  • Fully remote work for employees outside the predetermined commuting distance of SF, NY, London, or Berlin offices; otherwise in-office anchor days are Monday, Tuesday, and Friday.
Vercel

About Vercel

1,001-5,000 employees

Vercel builds a frontend cloud platform for developing, previewing, and deploying web applications, with strong support for React and Next.js. It sells usage-based and enterprise plans to developers and companies, and it stewards the open-source Next.js framework alongside tools like the AI SDK. Founded in 2015 and headquartered in San Francisco, the privately held company focuses on speeding up modern web development and delivery.

Contact me