Vercel logo
Vercel

Product Security Engineer

Posted on 20 August 2026

About the role

💼 What you will do

• Build the system that replaces one-report-at-a-time product security, since adding more triagers doesn't close the gap at Vercel's volume but building the systems that triage at scale does. • Focus on tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. • Go beyond triage by connecting a validated finding to its root cause and driving the fix, ideally with remediation proposed or opened automatically for well-understood vulnerability classes. • Rethink traditional security tooling for how Vercel actually operates, using agent-scale testing and automation in place of processes built for a much smaller company. • Build tooling that gives customers their own security testing capabilities for what they build on Vercel, not just hardening Vercel's own surface. • Work from the London, Berlin, New York, or San Francisco office on anchor days Monday, Tuesday, and Friday if you live within commuting distance, or fully remotely if you are further away.

📋 Job Requirements

• Be a builder first, with a strong software engineering background mattering more here than classic penetration testing experience. • Prefer building the system that triages a thousand reports to working through them one at a time. • Understand vulnerability triage and validation, or learn it quickly: how to assess an externally reported finding, reproduce it, judge severity, and see what makes that process hard to scale. • Be curious about, or already building with, agentic and LLM-based security tooling, with a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today and where they cannot. • Think in root causes and systems, defaulting to how this scales to the next ten thousand reports and why a class of bug happened rather than closing the ticket in front of you. • Feel comfortable defining a new practice, since agent-scale product security is not a mature discipline yet. • Know the web stack well, with strong familiarity in JavaScript, TypeScript, and Node.js runtime security plus modern web frameworks such as Next.js or React, so you can read and validate the code your tooling analyses.

🌟 Nice-to-have

• Have built or contributed to security automation used broadly across an engineering org. • Have run or triaged a bug bounty or vulnerability disclosure programme. • Have tested or secured multi-tenant platforms where customer-built applications run on shared infrastructure. • Have built systems that auto-generate or auto-propose code fixes rather than only findings. • Have thought about what security testing as a product capability could look like for a platform’s customers. • Hold relevant security certifications or recognitions such as OSCP, OSWE, CISSP, or bug bounty hall of fame entries.

🎯 Responsibilities

• Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility at a volume no manual process could match. • Build and operate LLM and agent-based reasoning that validates business logic, auth, and design-level findings rather than only matching known signatures. • Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened rather than the single report that came in. • Design systems that propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates. • Question which parts of the traditional product security toolkit still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them. • Own and evolve the bug bounty programme, managing researcher-facing scope, policy, and engagement alongside the internal tooling. • Extend the tooling and automation into a capability customers can use to test the security of what they build and deploy on the platform.

About Vercel

😃 What Vercel offers

• Receive a competitive compensation package including equity, with the San Francisco base range set at $208,000 to $312,000 and compensation outside San Francisco adjusted by location. • Access an inclusive healthcare package. • Learn and grow through mentorship and events that build your network and skills. • Take flexible time off. • Get the gear you need for the role plus a working from home budget to outfit your space.

💖 What makes Vercel unique

Vercel is the agentic infrastructure company, freeing people and agents to ship what comes next. For more than a decade it has shaped how the web is built, and as the team behind Next.js, v0, and the AI SDK it creates products that help builders move from idea to production with speed, security, and exceptional developer experience. Companies including OpenAI, PayPal, Ramp, and Supreme, along with millions of developers worldwide, build on the platform.

This position is no longer available, but we have other great opportunities!

Browse All Jobs

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.