Vercel logo
Vercel

Security Software Engineer, Open Source Frameworks

Posted on 20 August 2026

About the role

💼 What you will do

• Secure a broad portfolio of open source projects that power the modern web and run in millions of applications, focusing on Turborepo, Nuxt, Svelte and SvelteKit, SWR, Workflow, and Nitro. • Take on one of the highest-leverage security roles at the company, since a single structural fix at the framework level protects every one of those applications at once. • Find whole classes of vulnerability and eliminate them in one move rather than filing one bug at a time. • Run deep security assessments of framework internals covering routing, middleware, caching, server actions, and the build pipeline, then drive the framework-level fixes and design changes that remove entire families of bugs permanently. • Own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. • Work from the London, Berlin, New York, or San Francisco office on anchor days Monday, Tuesday, and Friday if you live within commuting distance, or fully remotely if you are further away.

📋 Job Requirements

• Have built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro, or found and reported security issues in them. This is a hard requirement rather than a preference. • Hold a deep appreciation and respect for open source work, treating these community projects and their maintainers with the seriousness they deserve. • Have 4+ years in security engineering, ideally with hands-on open source contribution experience including PRs rather than only filed issues. • Feel energised by root cause over remediation count, preferring the one design flaw that kills fifty potential bugs to closing fifty tickets. • Read framework internals rather than just application code, with strong JavaScript and TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood. • Stay pragmatic rather than theoretical, weighing real-world risk against maintainer and community bandwidth to land improvements that actually ship. • Bring vulnerability research chops, including structured assessment methodology, coordinated disclosure, handling embargoes, and writing clear advisories. • Communicate clearly, explaining a vulnerability, tradeoff, or design recommendation to maintainers, contributors, and non-security engineers alike. • Work comfortably in public, operating transparently with external researchers, maintainers, and the community.

🌟 Nice-to-have

• Have CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem. • Have maintained or heavily contributed to a widely used open source project. • Have experience with supply chain security tooling such as Sigstore, SLSA and provenance, or dependency and package scanning. • Have thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance. • Have run or triaged a bug bounty or vulnerability disclosure programme, ideally for open source projects.

🎯 Responsibilities

• Run deep security assessments of framework internals covering routing, middleware, caching, data fetching, server actions and RSC boundaries, and build tooling, to find the systemic design patterns producing whole families of issues. • Push design changes upstream that eliminate a category of vulnerability across every application built on the framework. • Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained projects. • Coordinate embargoed fixes, write and publish advisories, and manage the CVE and CNA process end to end. • Own triage and validation for Vercel's open source bug bounty programme, reproducing findings, assessing severity, and coordinating fixes with the right maintainers and researchers. • Partner with framework maintainers and core teams during RFCs and design review so new features ship with security considered from the first draft. • Build preventive tooling including linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes. • Own supply chain security, hardening how dependencies, releases, and published packages are built, signed, and distributed, and building review and provenance practices that keep AI-assisted contribution volume safe. • Engage directly with maintainers, contributors, and external researchers as peers, and represent Vercel in coordinated disclosure norms and working groups when an issue spans multiple ecosystems.

About Vercel

😃 What Vercel offers

• Receive a competitive compensation package including equity, with the San Francisco base range set at $208,000 to $312,000 and compensation outside San Francisco adjusted by location. • Access an inclusive healthcare package. • Learn and grow through mentorship and events that build your network and skills. • Take flexible time off. • Get the gear you need for the role plus a working from home budget to outfit your space.

💖 What makes Vercel unique

Vercel is the agentic infrastructure company, freeing people and agents to ship what comes next. For more than a decade it has shaped how the web is built, and as the team behind Next.js, v0, and the AI SDK it creates products that help builders move from idea to production with speed, security, and exceptional developer experience. Companies including OpenAI, PayPal, Ramp, and Supreme, along with millions of developers worldwide, build on the platform.

This position is no longer available, but we have other great opportunities!

Browse All Jobs

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.