
About Vercel
The front-end platform developers trust
Key Highlights
- Founded in 2015, originally as Zeit
- Over $563 million raised in Series D funding
- Popular Next.js framework used by major brands
- Serves clients like Meta, McDonald's, and Under Armour
Vercel, headquartered in Walnut, CA, is a leading Platform-as-a-Service (PaaS) provider specializing in front-end development. The company is known for its popular Next.js framework, which supports the Jamstack architecture, enabling developers to create fast and secure websites. With over $563 mill...
π Benefits
Vercel offers an inclusive healthcare package, unlimited PTO with a recommended 4 weeks off per year, and stock options. Employees enjoy a flexible wo...
π Culture
Vercel fosters a culture focused on optimizing the development and deployment experience. As a remote-first company, it values flexibility and inclusi...

Security Engineer β’ Senior
Vercel β’ United States - Remote
Overview
Vercel is hiring a Senior Product Security Engineer to drive critical product security initiatives across their platform. You'll focus on threat modeling, secure code review, and SDLC tooling. This role requires expertise in Next.js and Node.js.
Job Description
Who you are
You have 5+ years of experience in product security, with a strong focus on threat modeling and secure coding practices β you've successfully led security initiatives in fast-paced environments and understand the importance of embedding security throughout the software development lifecycle. Your expertise in open-source software security and bug bounty program management sets you apart, as you have a proven track record of enhancing security measures in complex systems.
You are well-versed in security frameworks and best practices, particularly OWASP standards β your ability to conduct thorough secure code reviews and identify vulnerabilities in applications is a key strength. You thrive in collaborative settings, working closely with product engineering teams to ensure that security is a priority from the initial design phase through to deployment.
As a senior member of the security team, you are a champion for a security-first culture within the organization β you enjoy mentoring junior engineers and sharing your knowledge to foster a deeper understanding of security practices across teams. Your communication skills allow you to effectively convey complex security concepts to both technical and non-technical stakeholders.
What you'll do
In this role, you will lead cross-organizational security projects, ensuring that Vercelβs core infrastructure and products are secure β you will work closely with product teams to integrate security measures into their workflows, providing guidance on best practices and compliance requirements. Your responsibilities will include managing the bug bounty program, where you will engage with external security researchers to identify and remediate vulnerabilities.
You will also focus on enhancing the security of the open-source ecosystems that Vercel contributes to, ensuring that the tools and libraries used by developers are secure and reliable. Your work will have a significant impact on the trust developers and end-users place in Vercelβs products, as you will be instrumental in shaping the security posture of the organization.
What we offer
Vercel provides a dynamic work environment where innovation and collaboration are at the forefront β you will have the opportunity to work with cutting-edge technologies and contribute to projects that are shaping the future of web development. We encourage you to apply even if your experience doesn't match every requirement, as we value diverse perspectives and backgrounds. Join us in our mission to empower developers and create a secure, AI-native web.
Interested in this role?
Apply now or save it for later. Get alerts for similar jobs at Vercel.
Similar Jobs You Might Like
Based on your interests and this role

Security Engineer
Life360 is hiring a Staff Product Security Engineer to safeguard their products and customers from evolving threats. You'll work in a remote-first environment, collaborating with a diverse team of cybersecurity professionals. This role requires expertise in embedding security into product development and infrastructure.

Security Engineer
Databricks is hiring a Staff Product Security Engineer to enhance the security of their software development lifecycle. You'll focus on security design reviews, threat modeling, and vulnerability management. This role requires expertise in security practices and tools.

Security Engineer
Crusoe is hiring a Senior Product Security Engineer to safeguard AI/ML focused cloud products. You'll lead security best practices and conduct assessments using tools like Kubernetes and Docker. This role requires significant experience in security engineering.

Security Engineer
Databricks is hiring a Staff Product Security Engineer to enhance the security of their software development lifecycle. You'll focus on threat modeling, security design reviews, and incident response. This role requires expertise in security practices and tools.

Security Engineer
Databricks is hiring a Staff Product Security Engineer to enhance the security of their software development lifecycle. You'll focus on threat modeling, security design reviews, and incident response. This role requires expertise in security practices and tools.