Product Security Engineer

Vercel Inc.

San Francisco, New York (CA, NY)

Hybrid

USD 208,000 - 312,000

Full time

42 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Vercel Inc. is seeking an engineer to build systems that triage externally reported security findings at scale, using agent-based reasoning and LLMs to assess validity, severity, and reproducibility.

The role aims to connect validated findings to root causes and drive automated remediation across a multi-tenant platform. You would rethink security tooling for agent-scale testing, enabling customers to test security of their deployments on Vercel, and contribute to a scalable security engineering

Responsibilities

  • Build tooling to triage and validate bug bounty and external findings at scale.
  • Push triage beyond pattern matching into agent-based analysis with LLMs.
  • Go from validated finding to root cause and fix with systemic remediation.
  • Rethink traditional security tooling for scale and replace or augment with agent-driven tooling.
  • Own and evolve the bug bounty program, including scope, policy, and engagement.
  • Build customer-facing security testing capabilities for their platforms.

Job description

Hybrid - San Francisco, New York City, London

About Vercel:

Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. For more than a decade we've helped builders move from idea to production with speed, security, and exceptional developer experience.

Now we're scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.

About the Role:

Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does.

This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes.

More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel's own surface.

Because of this, we're optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we're looking for.

If you're based within a pre-determined commuting distance of one of our offices (SF, NY, or London), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:
  • Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match.
  • Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures.
  • Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in.
  • Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place.
  • Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them.
  • Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one.
  • Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform.
About You:
  • You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for.
  • Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale.
  • Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet.
  • Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you.
  • Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook.
Bonus If You:
  • Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
  • Have experience running or triaging a bug bounty / vulnerability disclosure program.
  • Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
  • Have built systems that auto-generate or auto-propose code fixes, not just findings.
  • Have thought about what security testing as a product capability could look like for a platform's customers.
  • Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.
  • Competitive compensation package, including equity.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

  • Equal Opportunity:Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Vercel • New York (NY)

On-site
USD 208,000 - 312,000
Equity
Healthcare
Mentorship
+2
Product Security Engineer
Product Security Engineer

vercel.com • San Francisco (CA)

On-site
USD 208,000 - 312,000
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Flexible Time Off.
+1
Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

Cacheflow • San Francisco (CA)

On-site
USD 208,000 - 312,000
Equity
Health Insurance
Mentorship & Networking
+2
Security Engineer, Detection Response
Security Engineer, Detection Response

Vercel Inc. • San Francisco (CA), New York (NY)

Hybrid
USD 208,000 - 312,000
Equity
Mentorship & events
Flexible time off
+1
Vercel: Security Engineer, Cloud Vercel
Vercel: Security Engineer, Cloud Vercel

Mosaec • San Francisco (CA)

Hybrid
USD 208,000 - 312,000
Equity
Healthcare
Mentorship & events
+2
Security Engineer, Detection Response Berlin, London, New York City, San Francisco
Security Engineer, Detection Response Berlin, London, New York City, San Francisco

vercel.com • San Francisco (CA)

On-site
USD 208,000 - 312,000
Equity
Healthcare
Mentorship and events
+2
Software Engineer, Trust & Safety
Software Engineer, Trust & Safety

Vercel • San Francisco (CA)

On-site
USD 196,000 - 294,000
Equity
Healthcare Package
Mentorship and events
+2
Software Engineer, Trust & Safety
Software Engineer, Trust & Safety

Jobless • New York (NY)

On-site
USD 196,000 - 294,000
Equity
Inclusive Healthcare Package
Mentorship and events
+2
Software Engineer, Trust & Safety New York City, San Francisco
Software Engineer, Trust & Safety New York City, San Francisco

vercel.com • San Francisco (CA), Northern (KY)

On-site
USD 196,000 - 294,000
Equity
Healthcare
Mentorship and events
+2
Software Engineer, Backend
Software Engineer, Backend

Vercel Inc. • United States

Hybrid
USD 196,000 - 294,000
Equity
Mentorship & events
Flexible time off
+1