Security Software Engineer, Open Source Frameworks

Vercel

San Francisco (CA)

Hybrid

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vercel is seeking a security engineer who enjoys identifying broad vulnerability classes and eliminating them at the source. You will perform deep security assessments of framework internals and own how reported issues are coordinated across OSS projects such as Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro.

You will drive design changes to remove classes of vulnerabilities, manage coordinated disclosures, and own the OSS bug bounty program.

Qualifications

  • Experience building security tooling and automations.
  • Deep understanding of security vulnerabilities in modern web frameworks and OSS.
  • Familiarity with coordinated disclosure and CVE processes.

Responsibilities

  • Hunt for vulnerability classes by running deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions, build tooling).
  • Drive root-cause framework fixes by pushing upstream design changes that prevent categories of vulnerabilities across all apps.
  • Own vulnerability disclosure and CVEs: triage reports, coordinate embargoed fixes, write advisories and manage CVE/CNA processes end to end.
  • Run the OSS bug bounty program: triage, validate reports, reproduce findings, coordinate fixes with maintainers and researchers.
  • Get security into design early: collaborate with maintainers during RFCs and design reviews to ship secure features from the start.
  • Build preventive tooling: contribute linters, codemods, and CI checks to prevent regressions of vulnerability classes.
  • Own supply chain security for these projects: review dependencies, releases and package publishing, especially with AI-assisted contributions.
  • Work with the community: engage maintainers and researchers as peers and advocate for coordinated disclosure norms.

Job description

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role

Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro . A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company.

We\'re looking for a security engineer who loves finding a whole class of vulnerability and eliminating it in one move, not someone who\'s satisfied filing one bug at a time. You\'ll run deep security assessments of framework internals (routing, middleware, caching, server actions, the build pipeline), find the systemic patterns that produce entire families of bugs, and drive the framework-level fixes and design changes that remove them permanently. You\'ll also own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. This includes hands-on ownership of Vercel\'s open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right maintainers.

What you will do
  • Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues.
  • Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they\'re reported.
  • Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end.
  • Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel\'s open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers.
  • Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in.
  • Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before they land again.
  • Own supply chain security for these projects: Harden how dependencies, releases, and published packages for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro are built, signed, and distributed. As more contributions and dependency updates are generated or assisted by AI agents, build the review and provenance practices that keep that increased volume safe.
  • Work with the community, not around it: Engage directly with maintainers, contributors, and external researchers as peers. Bring pragmatic security recommendations to project discussions in a way that respects how these projects actually get built, and represent Vercel in coordinated disclosure norms and working groups when an issue spans multiple ecosystems.
About you
  • You\'ve actually used or broken these frameworks: You\'ve built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects), or you\'ve found and reported security issues in them. This is a hard requirement, not a nice-to-have: we need someone who understands what these projects actually do and how they\'re actually used, not a generalist parachuting in.
  • You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them, and you treat that with the seriousness it deserves. You\'re not here to slow the project down with
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

Cacheflow • San Francisco (CA)

On-site
USD 208,000 - 312,000
Equity
Health Insurance
Mentorship & Networking
+2
Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

vercel.com • Town of Berlin (NY)

On-site
USD 208,000 - 312,000
Equity in compensation
Inclusive Healthcare Package
Mentorship and growth opportunities
+2
Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

Vercel • New York (NY)

On-site
USD 208,000 - 312,000
Competitive compensation package
Equity
Inclusive Healthcare Package
+3
Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 155,000 - 190,000
Competitive compensation
Equity
Healthcare package
Security Engineer - Open Source Frameworks & Bug Bounty
Security Engineer - Open Source Frameworks & Bug Bounty

Vercel • New York (NY)

On-site
USD 208,000 - 312,000
Competitive compensation package
Equity
Inclusive Healthcare Package
+3
Product Security Engineer
Product Security Engineer

Vercel • San Francisco (CA)

Hybrid
USD 140,000 - 220,000
Security Engineer for Open Source Frameworks
Security Engineer for Open Source Frameworks

Vercel • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Security Engineer for Open-Source Web Frameworks
Security Engineer for Open-Source Web Frameworks

Vercel • San Francisco (CA)

On-site
USD 208,000 - 312,000
Equity
Health Insurance
Mentorship & Networking
+2
Product Security Engineer
Product Security Engineer

Vercel • New York (NY)

Hybrid
USD 208,000 - 312,000
Equity
Healthcare
Mentorship
+2
Product Security Engineer
Product Security Engineer

Vercel • United States

On-site
USD 208,000 - 312,000
Competitive compensation package
Flexible Time Off
Mentorship and professional development