Security Software Engineer, Open Source Frameworks
The vacancy is well-structured with clear responsibilities and requirements, though compensation details could be more explicit.
Check Match β Just drop your CV
See your fit for Security Software Engineer, Open Source Frameworks in seconds.
Overview
Join Vercel as a Security Software Engineer focusing on open source frameworks. Drive security assessments, manage vulnerabilities, and enhance security practices in a hybrid work environment. About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship whatβs next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.
What you will do
- β’Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues.
- β’Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they're reported.
- β’Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects.
- β’Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel's open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro.
- β’Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in.
- β’Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before they land again.
- β’Own supply chain security for these projects: Harden how dependencies, releases, and published packages for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro are built, signed, and distributed.
- β’Work with the community, not around it: Engage directly with maintainers, contributors, and external researchers as peers.
Benefits
- β’Competitive compensation package, including equity.
- β’Inclusive Healthcare Package.
- β’Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- β’Flexible Time Off.
- β’We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
About you
- β’You've actually used or broken these frameworks: You've built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects).
- β’You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them.
- β’4+ years in security engineering, ideally with real hands-on open source contribution experience.
- β’You can read framework internals, not just application code: Strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood.
- β’Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes.
- β’Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike.