This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a Senior Product Security Engineer to join our security team to drive critical product security initiatives across Vercel’s products and platform. Your core focus will be on threat modeling, open-source software security, secure code review, SDLC tooling, and bug bounty program management. You will support both our internal product engineering teams and customer-facing security programs, ensuring that security is embedded throughout our development lifecycle and that our platform earns the trust of developers and end-users alike.
Job Responsibility:
Partner with engineering and product teams to perform threat modeling for new and existing features
Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend
Oversee Vercel’s open-source security efforts
Evaluate, select, and integrate security tools into our Software Development Life Cycle
Own and expand Vercel’s bug bounty program
Lead and contribute to security projects that span multiple teams and disciplines
Work closely with customer success and product marketing on security-related initiatives that impact our users
Requirements:
5+ years of experience in a Product Security or Product Security role (or related field)
Strong familiarity with JavaScript/TypeScript and Node.js runtime security
Experience with modern web frameworks (ideally Next.js or React and Node-based frameworks)
Demonstrated ability to perform threat modeling and architectural risk analysis for complex product
Hands-on experience with product security tooling such as static product security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration
Knowledge of open-source security best practices
Exposure to running or participating in a bug bounty program or vulnerability disclosure process
Solid understanding of cloud architecture and serverless environments from a security perspective
Proven ability to drive security initiatives and influence engineering teams to adopt best practices
Nice to have:
Prior software development experience beyond security (e.g. as a frontend or backend engineer)
Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries)
Experience with security policy-as-code or infrastructure as code security
Have built or implemented security features in a product (such as authentication systems, encryption, secure CI/CD pipelines) or contributed to security community projects/tools
An active participant in the security community (e.g., contributing to open source security projects, writing blog posts or research, attending or speaking at security conferences)
What we offer:
Competitive compensation package, including equity
Inclusive Healthcare Package
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills
Flexible Time Off
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed