Senior Security Software Engineer, v0

Webhosting

Berlin

On-site

EUR 180,695 - 271,043

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Vercel is seeking a Senior Security focused software engineer to embed with the v0 team in a hybrid Berlin-based role. You will own security end-to-end, design sandboxing and isolation controls, and work with HackerOne researchers to triage and remediate reports.

You’ll review new features, defend against threats, and ship secure code with strong engineering judgment. You will operate with independence, set security bar, and collaborate across teams while balancing velocity and risk in a

Qualifications

  • Senior IC4 software engineer with strong security background.
  • Experience shipping production web applications with security focus.
  • Ability to own security end-to-end for a product.

Responsibilities

  • Find and fix vulnerabilities across v0 and ship fixes.
  • Build security features into the product, including sandboxing and isolation.
  • Review all new v0 features and launches before release.
  • Own HackerOne relationship and drive fixes with researchers.
  • Own the v0 threat model and defense against prompt injection.
  • Harden code execution boundaries and sandboxed environments.
  • Create guardrails that enable fast shipping without reintroducing bugs.
  • Collaborate with Product Security and define tradeoffs for v0.

Skills

Security engineering
Code review
Sandboxing
AuthN/AuthZ design
TypeScript
React
Node.js
Security threat modeling

Job description

Vercel ·Berlin, Hybrid - San Francisco, New York City, London

Hybrid Full-time Senior Security

Job Description

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies likeOpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role

v0 turns natural language into working, deployed applications. An agent writes code, executes it, and ships it on a user’s behalf. That makes v0 one of the most interesting and highest-stakes security surfaces at Vercel: sandboxed code execution, multi-tenant isolation, permission boundaries between what a user asked for and what the agent actually did, and resistance to prompt injection and tool misuse.

We’re looking for a Senior (IC4) software engineer with a strong security background to sit fully embedded inside the v0 team, not as a rotating auditor who reviews designs and files tickets, but as a peer engineer who owns security end to end for everything v0 ships. That means finding and fixing vulnerabilities yourself, building security features directly into the product, reviewing every new feature and launch before it goes out, and running the relationship with our HackerOne researcher community for anything v0-related. You’ll spend real time being a great generalist engineer: building features, fixing bugs, shipping to production alongside the rest of the team. The difference is that you bring security judgment and hands‑on ownership to everything the team builds, and you’re the one who catches the sandbox escape, the auth gap, or the injection vector before it ships, rather than after.

This role reports into the security organization but is deployed full‑time with v0, and is evaluated as much on shipped product velocity as on security outcomes. As a senior (IC4) engineer, you’re expected to operate independently, set the security bar for the team, and be trusted to make the final call on v0‑specific tradeoffs.

What you will do

  • Find and fix issues yourself:Proactively hunt for vulnerabilities across v0, from code you’re reviewing to systems you’re actively poking at, and ship the fix, not just the finding.
  • Build security features directly into the product:Design and implement the security‑facing functionality itself (sandboxing/isolation controls, permission boundaries, abuse detection, safe defaults for generated apps) as a normal part of the v0 roadmap, not a side project.
  • Review all new v0 features and launches:Be the security reviewer of record for everything the team ships (new capabilities, generated‑app patterns, integrations) before it goes out the door.
  • Own the HackerOne relationship for v0:Triage, validate, and drive fixes for reports from Vercel’s HackerOne researcher community that touch v0, and work directly with researchers on reproduction and remediation.
  • Own the v0 threat model:Understand and continuously refine how v0 generates, executes, and deploys code, including sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool‑use abuse.
  • Harden code execution boundaries:Work directly on how agent‑generated code is scoped, sandboxed, and constrained before it touches real infrastructure, including Vercel’s own sandbox and serverless runtimes.
  • Build guardrails that don’t slow the team down:Create patterns, libraries, and checks that let v0 engineers ship new generated‑app capabilities quickly without reintroducing known bug classes (auth, SSRF, injection) each time.
  • Partner with central Product Security:Share threat models, incident learnings, and SDLC tooling with the broader security team, while making the final call on v0‑specific tradeoffs since you have the deepest context on the product.
  • Respond to v0‑specific security reports and incidents:Be the first responder and technical owner when a security issue is reported against v0 specifically.
  • Think like an attacker, and like an agent:Reason about how a user, or an agent acting on that user’s behalf, could misuse v0 to attack itself, other tenants, or the platform underneath it.
  • You’re a software engineer first:5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior). You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role.
  • Strong full‑stack fundamentals:Comfortable in TypeScript, React, and Node, and able to work in the same codebase, PR flow, and velocity as the rest of the v0 team.
  • Real security judgment:You understand authN/authZ design, sandboxing and isolation, injection vulnerability classes, and can reason about “an AI agent writing and running code” as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title.
  • You influence through code, not just process:You’d rather fix the root cause in a PR than write a policy doc about it. You can be the security conscience of a fast‑moving team without becoming its bottleneck.
  • Comfortable with ambiguity:v0’s threat model is still being written. You’re excited to define it rather than inherit a mature playbook.
  • Willing to build with v0, not just secure it:You’re happy to actually go use v0 to build things and understand how our products work end to end, not just read the code from the outside.

Bonus if you have

The San Francisco, CA base pay range for this role is $208,000.00 – $312,000.00. Actual salary will be based on job‑related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity‑based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer, Detection Response
Security Engineer, Detection Response

Vercel Inc. • Berlin

Hybrid
EUR 185,000 - 277,000
Equity
Healthcare
Mentorship & events
+2
Product Security Engineer
Product Security Engineer

Vercel • Germany

Hybrid
EUR 90,000 - 130,000
Software Engineer, Compute
Software Engineer, Compute

Vercel Inc. • Germany

Hybrid
EUR 106,000 - 153,000
Equity
Healthcare package
Mentorship & events
+2
(Principal) Senior Security Engineer
(Principal) Senior Security Engineer

vay • Berlin

On-site
EUR 110,000 - 150,000
ESOP stock options
Unlimited Paid Vacation Days
Relocation financial assistance
+2
Head of Solutions Architecture, EMEA
Head of Solutions Architecture, EMEA

Vercel Inc. • Germany

Hybrid
EUR 150,000 - 210,000
Equity
Healthcare
Mentorship programs
+2
Partner Solutions Engineer, EMEA
Partner Solutions Engineer, EMEA

vercel.com • Berlin

On-site
EUR 120,000 - 170,000
Competitive compensation
Equity
Healthcare package
+2
Partner Solutions Engineer, EMEA
Partner Solutions Engineer, EMEA

Vercel Inc. • Germany

Hybrid
EUR 90,000 - 130,000
Competitive compensation
Equity
Healthcare package
+1
Senior Product Security Engineer (Embedded / Automotive)
Senior Product Security Engineer (Embedded / Automotive)

Cybermindspace • Berlin

Hybrid
EUR 90,000 - 150,000
Stock options
Unlimited vacation
Germany ticket Berlin
+4
Senior Full Stack Engineer
Senior Full Stack Engineer

aiomics • Berlin

On-site
EUR 100,000 - 150,000
Opportunity for equity participation
Immediate real-world impact
Cutting-edge technology stack
Senior Security Engineer - AppSec (d/f/m)
Senior Security Engineer - AppSec (d/f/m)

JobCubby • Germany

Hybrid
EUR 90,000 - 130,000