Product Security Engineer
Core
Drive critical product security initiatives across Vercel's platform, focusing on threat modeling, secure code review, open-source security, SDLC tooling, and bug bounty management.
Role type
Senior Product Security Engineer
Builds
Vercel's core infrastructure and products (Next.js, Node.js, serverless architecture) and open-source ecosystems
Domain
Web security, Open Source Security, SDLC Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Threat modeling, Secure code review, Open-source security management, SDLC tooling & automation, Bug bounty program management, Cross-organizational security leadership, Customer-facing security support
Preferred skills
Software development experience (frontend/backend), Security certifications (OSCP, OSWE, CISSP), Policy-as-code/Infrastructure-as-code security, Building security features in products, Active security community participation
Technologies
Next.js, Node.js, JavaScript, TypeScript, GitHub Advanced Security (GHAS), SAST, DAST, Dependabot, Snyk, Open Policy Agent, Terraform
Responsibilities
Perform threat modeling for new and existing features; Conduct secure code reviews and security assessments; Oversee open-source security efforts (consumer and contributor); Evaluate and integrate security tools into CI/CD pipelines; Own and expand the bug bounty program; Lead cross-organizational security initiatives; Support customer security questionnaires and audits
Seniority
Senior, hands-on IC with leadership scope