🏢
Vercel
Product Security Engineer
Job Description
ABOUT THE ROLE
We are seeking a highly skilled Product Security Engineer to join our security team at Vercel. As a critical member of our team, you will drive product security initiatives across our products and platform, ensuring the security and trustworthiness of our infrastructure and services. Your expertise will be instrumental in shaping the security of our platform, influencing the security of open-source ecosystems, and building a security-first culture within our engineering organization.
WHAT YOU'LL DO
As a Product Security Engineer, you will be responsible for leading and contributing to various security initiatives, including:
- Threat modeling and design review: Partner with engineering and product teams to identify potential security risks and recommend controls or design changes to mitigate threats.
- Secure code review: Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
- Open-source security management: Oversee Vercel's open-source security efforts, including monitoring and coordinating fixes for vulnerabilities in third-party open-source packages and ensuring the security of open-source projects we maintain and publish.
- SDLC tooling and automation: Evaluate, select, and integrate security tools into our Software Development Life Cycle, driving the implementation of automated security checks in our CI/CD pipelines and GitHub workflows.
- Bug bounty program management: Own and expand Vercel's bug bounty program, triaging and validating incoming vulnerability reports, and coordinating cross-team efforts to remediate and learn from reported vulnerabilities.
- Cross-organizational security initiatives: Lead and contribute to security projects that span multiple teams and disciplines, driving lasting security improvements across the organization.
- Customer-facing security support: Work closely with customer success and product marketing on security-related initiatives that impact our users, contributing to security documentation and whitepapers, and communicating our security features and best practices to build customer trust in the platform.
WHAT YOU'LL NEED
To succeed in this role, you should have:
- 5+ years of experience in a Product Security or Product Security role (or related field), with a track record of securing web products and services.
- In-depth knowledge of web application security, secure coding practices, and threat modeling.
- Experience with secure code review, vulnerability management, and bug bounty programs.
- Strong understanding of software development life cycles, CI/CD pipelines, and GitHub workflows.
- Excellent communication and collaboration skills, with the ability to work effectively with cross-functional teams.
- Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks.
WHY REMOTE
This role is fully remote, with the flexibility to work from anywhere. As a remote employee, you will have the opportunity to work with a talented team of security professionals, contribute to the security of our platform, and enjoy a range of benefits and perks.
BENEFITS
- Competitive salary and benefits package
- Flexible schedule and remote work arrangement
- Opportunity to work with a talented team of security professionals
- Professional development and growth opportunities
- Access to cutting-edge security tools and technologies
- Collaborative and dynamic work environment