Senior Product Security Engineer at Vercel

This role is ideal for a senior security professional with at least 5 years of experience who is deeply embedded in the modern web ecosystem. You should be a Ja

Work type: remote

Location: Remote - United States

Salary: $196,000 – $294,000/yr

Type: Full-time

Summary

This role is ideal for a senior security professional with at least 5 years of experience who is deeply embedded in the modern web ecosystem. You should be a JavaScript/TypeScript expert who understands the nuances of Node.js and Next.js, as you'll be securing both internal infrastructure and high-profile open-source projects. This is a high-autonomy position that blends deep technical audits with strategic leadership. The compensation is highly competitive ($196k–$294k plus equity) for a fully remote U.S. role. Working at Vercel offers unique "industry-shaping" impact, as your security decisions will influence the millions of developers using their platform and open-source tools like Next.js. You’ll also enjoy a flexible remote culture, a dedicated WFH budget, and the chance to manage a world-class bug bounty program. **You might be a good fit if you...** * Have extensive experience with threat modeling and securing serverless/cloud-native architectures. * Are comfortable conducting deep-dive secure code reviews in TypeScript and Node.js. * Enjoy collaborating with the open-source community and managing vulnerability disclosures. * Want to build automated security guardrails directly into CI/CD pipelines using tools like GitHub Advanced Security.

Job Description

## About Vercel:

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

## About the Role:

We are looking for a Senior Product Security Engineer to join our security team to drive critical product security initiatives across Vercel’s products and platform. Your core focus will be on threat modeling, open-source software security, secure code review, SDLC tooling, and bug bounty program management. You will support both our internal product engineering teams and customer-facing security programs, ensuring that security is embedded throughout our development lifecycle and that our platform earns the trust of developers and end-users alike.

As a senior member of the team, you will lead cross-organizational security projects and champion a security-first culture within Vercel’s engineering organization. This is a high-impact role with broad scope – your work will not only secure Vercel’s core infrastructure and products (built with Next.js, Node.js, and serverless architecture), but also influence the security of the open-source ecosystems we contribute to.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

## What You Will Do:








## About You:









## Bonus If You:






##

## Benefits:






The San Francisco, CA base pay range for this role is $196,000.00 - $294,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

View this job on nocollar jobs