• Build the systems that triage and validate bug bounty and externally reported security findings at scale, reasoning about validity, severity, and reproducibility at volume.
• Rethink traditional security tooling for how Vercel actually operates — agent-scale testing and automation in place of processes built for a much smaller company.
• This is a mandate to build, not to do manual penetration testing — a software engineer moving into security or a security engineer with a strong engineering background is exactly who Vercel is looking for.
• Available in London, Berlin, New York, or San Francisco. If based within commuting distance of the London office, the role includes in-office anchor days on Monday, Tuesday, and Friday. Otherwise the role is fully remote.
📋 Job Requirements
• Be a builder first — a strong software engineering background is more important here than classic penetration testing experience.
• Understand vulnerability triage and validation, even if that's not your primary background — you know how to assess an externally reported finding, reproduce it, and judge severity.
• Be curious about, or already building with, agentic and LLM-based security tooling, with a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today.
• Default to root cause and systems thinking — "how do I make this scale to the next ten thousand reports" rather than closing the one ticket in front of you.
• Be comfortable defining a new practice — agent-scale product security isn't a mature discipline yet.
• Have strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks, ideally Next.js or React and Node-based frameworks.
🌟 Nice-to-have
• Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
• Have experience running or triaging a bug bounty or vulnerability disclosure programme.
• Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
• Have built systems that auto-generate or auto-propose code fixes, not just findings.
• Have thought about what security testing as a product capability could look like for a platform's customers.
• Hold relevant security certifications or recognitions such as OSCP, OSWE, CISSP, or notable bug bounty hall-of-fame entries.
🎯 Responsibilities
• Build tooling to triage and validate bug bounty and external findings at scale, designing systems that automatically assess validity, severity, and reproducibility.
• Push triage beyond pattern matching into agentic analysis, building LLM/agent-based reasoning that can validate business logic, auth, and design-level findings.
• Trace validated findings back to the underlying pattern or class so the team fixes the reason it happened, not just the one report.
• Build toward automated remediation — design systems that can propose and open fixes for well-understood vulnerability classes with appropriate human review gates.
• Question which parts of the traditional product security toolkit still make sense at Vercel's scale and build the agent-driven tooling that replaces or augments them.
• Own and evolve the bug bounty programme, managing the researcher-facing side and the internal tooling.
• Build toward customer-facing security testing capabilities that extend internal tooling into a capability customers can use.
About Vercel
😃 What Vercel offers
• Receive competitive compensation package, including equity.
• Get an inclusive healthcare package.
• Access mentorship and events that help you build your network and skills.
• Take flexible time off.
• Receive gear for your role and a work-from-home budget to outfit your space.
💖 What makes Vercel unique
Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. As the team behind Next.js, v0, and AI SDK, Vercel creates products that help builders move from idea to production with speed, security, and exceptional developer experience. Trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.