• Secure Vercel's broad portfolio of open source projects that power the modern web, running in millions of applications — a single structural fix at the framework level protects every one of those applications at once.
• Primary focus on Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro.
• Find whole classes of vulnerabilities and eliminate them in one move, not file one bug at a time.
• Available in London, Berlin, New York, or San Francisco. If based within commuting distance of the London office, the role includes in-office anchor days on Monday, Tuesday, and Friday. Otherwise the role is fully remote.
📋 Job Requirements
• Have actually used or broken these frameworks — built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro, or found and reported security issues in them. This is a hard requirement.
• Have a deep appreciation and respect for open source work, understanding these are community projects with maintainers and contributors who care deeply about them.
• Have 4+ years in security engineering, ideally with real hands-on open source contribution experience including sending PRs, not just filing issues.
• Be energised by root cause, not remediation count — finding the one design flaw that kills fifty potential bugs.
• Be able to read framework internals, not just application code — strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood.
• Be pragmatic, not theoretical — able to weigh real-world risk against maintainer and community bandwidth.
• Have vulnerability research chops with experience in structured security assessment methodology and coordinated/responsible disclosure processes.
• Be a clear communicator who can explain a vulnerability, a tradeoff, or a design recommendation to maintainers, contributors, and non-security engineers alike.
• Be comfortable operating in public with external researchers, maintainers, and the community.
🌟 Nice-to-have
• Have CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem.
• Have maintained or heavily contributed to a widely used open source project.
• Have experience with supply chain security tooling such as Sigstore, SLSA/provenance, dependency and package scanning.
• Have thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance.
• Have run or triaged for a bug bounty or vulnerability disclosure programme before, ideally for open source projects.
🎯 Responsibilities
• Run deep security assessments of framework internals including routing, middleware, caching, data fetching, server actions/RSC boundaries, and build tooling to find systemic design patterns that produce whole families of issues.
• Push design changes upstream that eliminate a category of vulnerability across every application built on the framework.
• Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects.
• Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end.
• Own triage and validation of incoming reports to Vercel's open source bug bounty programme.
• Partner with framework maintainers and core teams during RFCs and design review so new features ship with security considered from the first draft.
• Contribute linters, codemods, and CI checks that catch regressions of previously fixed vulnerability classes.
• Harden how dependencies, releases, and published packages are built, signed, and distributed.
• Engage directly with maintainers, contributors, and external researchers as peers, representing Vercel in coordinated disclosure norms and working groups.
About Vercel
😃 What Vercel offers
• Receive competitive compensation package, including equity.
• Get an inclusive healthcare package.
• Access mentorship and events that help you build your network and skills.
• Take flexible time off.
• Receive gear for your role and a work-from-home budget to outfit your space.
💖 What makes Vercel unique
Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. As the team behind Next.js, v0, and AI SDK, Vercel creates products that help builders move from idea to production with speed, security, and exceptional developer experience. Trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.