Senior Product Security Engineer

Vercel Vercel · Enterprise · AMER · Security

Senior Product Security Engineer at Vercel, focusing on threat modeling, open-source security, secure code review, SDLC tooling, and bug bounty program management for Vercel's products and platform, including those built with Next.js, Node.js, and serverless architecture.

What you'd actually do

  1. Partner with engineering and product teams to perform threat modeling for new and existing features.
  2. Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
  3. Oversee Vercel’s open-source security efforts.
  4. Evaluate, select, and integrate security tools into our Software Development Life Cycle.
  5. Own and expand Vercel’s bug bounty program.

Skills

Required

  • Product Security
  • threat modeling
  • open-source software security
  • secure code review
  • SDLC tooling
  • bug bounty program management
  • JavaScript/TypeScript
  • Node.js runtime security
  • modern web frameworks
  • Next.js
  • architectural risk analysis

Nice to have

  • React
  • serverless backend

What the JD emphasized

  • 5+ years of experience in an Product Security or Product Security role
  • understand how to integrate security into a fast-paced SDLC without slowing it down
  • Experience implementing or working with secure development lifecycle practices (secure design, code review, pentesting, etc.) is required