Security Software Engineer, Open Source Frameworks
Core
Hunt for systemic vulnerability classes in open source frameworks (Turborepo, Nuxt, SvelteKit, etc.) and drive root-cause design fixes to protect millions of applications.
Role type
Senior IC security software engineer (open source frameworks)
Builds
Open source frameworks (Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro) and their security infrastructure
Domain
Web development, open source security, JavaScript/TypeScript ecosystem
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
deep framework internals knowledge (routing, middleware, caching, server actions, build pipelines), vulnerability research methodology, coordinated disclosure management, supply chain security practices, JavaScript/TypeScript fundamentals, open source community engagement, linter/codemod development, CVE/CNA process management
Preferred skills
CVE credits or published security research, experience maintaining widely used open source projects, supply chain security tooling expertise (Sigstore, SLSA), AI-agent contribution risk modeling, bug bounty program triage experience
Technologies
Turborepo, Nuxt, Svelte, SvelteKit, SWR, Workflow, Nitro, JavaScript, TypeScript, Sigstore, SLSA
Responsibilities
Run deep security assessments of framework internals to find systemic design patterns producing families of issues; Drive root-cause framework fixes that eliminate categories of vulnerabilities; Own vulnerability disclosure and CVEs including triaging reports and managing the CVE/CNA process; Run the OSS bug bounty program for maintained projects; Get security into design early by partnering with maintainers during RFCs; Build preventive tooling like linters and CI checks; Own supply chain security for dependencies and published packages
Seniority
Senior, hands-on IC