wagey.ggwagey.gg
30,363  jobs30,363  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(30,363)/Security Engineer Role(368)/Vercel (41) - Security Software Engineer, Open Source Frameworks
Vercel

Vercel - Security Software Engineer, Open Source Frameworks

Hybrid - San Francisco, New York City, London, Berlin$208k - $312k+ Equity1w ago
In OfficeMidEMEAOil & GasLogisticsSecurity EngineerSoftware EngineerJavaScriptSvelteTypeScriptReportingVercel

Requirements

• CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem. • Maintained or heavily contributed to a widely used open source project. • Experience with supply chain security tooling (Sigstore, SLSA/provenance, dependency and package scanning). • Thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance. • Run or triaged for a bug bounty / vulnerability disclosure program before, ideally for open source projects.

Responsibilities

• Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues. • Hunt for vulnerability classes, not individual bugs: • Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they're reported. • Drive root-cause framework fixes: • Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end. • Own vulnerability disclosure and CVEs: • Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel's open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers. • Run the OSS bug bounty program for these projects: • Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in. • Get security into design early: • Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before they land again. • Build preventive tooling: • Own supply chain security for these projects: Harden how dependencies, releases, and published packages for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro are built, signed, and distributed. As more contributions and dependency updates are generated or assisted by AI agents, build the review and provenance practices that keep that increased volume safe. • Own supply chain security for these projects: • Work with the community, not around it: Engage directly with maintainers, contributors, and external researchers as peers. Bring pragmatic security recommendations to project discussions in a way that respects how these projects actually get built, and represent Vercel in coordinated disclosure norms and working groups when an issue spans multiple ecosystems. • Work with the community, not around it: • You've actually used or broken these frameworks: You've built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects), or you've found and reported security issues in them. This is a hard requirement, not a nice-to-have: we need someone who understands what these projects actually do and how they're actually used, not a generalist parachuting in. • You've actually used or broken these frameworks: • You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them, and you treat that with the seriousness it deserves. You're not here to slow the project down with process for its own sake. • You have a deep appreciation and respect for open source work: • 4+ years in security engineering, ideally with real hands-on open source contribution experience. You've actually sent PRs to projects like these, not just filed issues against them. • 4+ years in security engineering, • You're energized by root cause, not remediation count: Finding the one design flaw that kills fifty potential bugs is more satisfying to you than closing fifty tickets one at a time. • You're energized by root cause, not remediation count: • You can read framework internals, not just application code: Strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood (routing, SSR/RSC, middleware, bundling/build systems). • You can read framework internals, not just application code: • Pragmatic, not theoretical: You can weigh real-world risk against maintainer and community bandwidth, and land on security improvements that actually ship, rather than the theoretically ideal fix that never gets merged. • Pragmatic, not theoretical: • Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories. • Vulnerability research chops: • Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike, in writing and in conversation. • Clear communicator: • Comfortable operating in public: You're used to working transparently with external researchers, maintainers, and the community, not just inside a company's four walls. • Comfortable operating in public:

Benefits

• Competitive compensation package, including equity. • Inclusive Healthcare Package. • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills. • Flexible Time Off. • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed. • The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. • Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

VercelVercel - Senior Security Software Engineer, v01w ago
·Hybrid - San Francisco, New York City, London, Berlin·$208k - $312k/year + Equity
In OfficeEMEASeniorArtificial IntelligenceDeveloper ToolsSoftware EngineerSecurity EngineerVercelReportingReactTypeScriptFull Stack
VercelVercel - Software Engineer, Observability3w ago
·Hybrid - London·Equity
In OfficeEMEASeniorSoftware EngineerGoJavaScriptTypeScriptDocumentationVercel
n8nn8n - Community Software Engineer2mo ago
·Remote - Berlin, Berlin-Brandenburg, Germany·Equity
RemoteEMEAMidArtificial IntelligenceSoftware EngineerJavaScriptTypeScriptRESTnpmpnpm
Sony Music GlobalSony Music Global - Software Engineer, D2C5mo ago
·UK & Ireland, United Kingdom, London
In OfficeEMEAMidMental HealthCloud ComputingSenior CareData AnalyticsSoftwareSoftware EngineerPythonJavaScriptTypeScriptReactD2C
AnthropicAnthropic - Staff+ Software Engineer, Safeguards Infrastructure6mo ago
·London, UK - Hybrid·£255k - £325k/year/year + Equity
In OfficeEMEAMidBankingCommercial Real EstateArtificial IntelligenceSoftware EngineerSecurity EngineerStaff EngineerPythonRustTypeScriptClaude
bjakcareerbjakcareer - Software Engineer, Desktop3mo ago
·London, Greater London, United Kingdom
In OfficeEMEATransportationSoftware EngineerJavaScriptTypeScriptReactSQLite
VercelVercel - Senior Software Engineer, Trust & Safety5mo ago
·Remote - United States·$196k - $294k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSenior Software EngineerSoftware EngineerSecurity EngineerJavaScriptTypeScriptPythonVercelAWS
UpGuardUpGuard - Software Engineer (Multiple Levels)1mo ago
·Sydney / Melbourne / Hobart / Brisbane
In OfficeAPACMidCybersecurityArtificial IntelligenceSoftware EngineerSecurity EngineerGoJavaScriptReactKubernetes
runpodrunpod - Full Stack Security Engineer (Application & Product)1w ago
·Remote - USA·$152k - $175k/year + Equity
RemoteNASeniorSecurity EngineerSoftware EngineerGoPythonJavaScriptTypeScriptFull StackTeam ManagementProgram ManagementReportingRESTGraphQLDockerKubernetesWagmiSlack

Browse more by category

Show 368 moreSecurity EngineerShow 2,043 moreSoftware EngineerShow 1,171 moreJavaScriptShow 25 moreSvelteShow 1,923 moreTypeScriptShow 6,386 moreReportingShow 71 moreVercel
Privacy·Terms··Contact·FAQ·Wagey on X