• Own security end to end for v0, which turns natural language into working, deployed applications where an agent writes code, executes it, and ships it on a user's behalf.
• Work on one of the most interesting and highest-stakes security surfaces at Vercel, spanning sandboxed code execution, multi-tenant isolation, permission boundaries between what a user asked for and what the agent actually did, and resistance to prompt injection and tool misuse.
• Sit fully embedded inside the v0 team as a peer engineer rather than a rotating auditor who reviews designs and files tickets.
• Spend real time as a great generalist engineer, building features, fixing bugs, and shipping to production alongside the team, while bringing security judgement to everything it builds.
• Report into the security organisation while deployed full-time with v0, evaluated as much on shipped product velocity as on security outcomes.
• Work from the London, Berlin, New York, or San Francisco office on anchor days Monday, Tuesday, and Friday if you live within commuting distance, or fully remotely if you are further away.
📋 Job Requirements
• Be a software engineer first, with 5+ years building and shipping production web applications at a level where you operate independently.
• Bring strong full-stack fundamentals in TypeScript, React, and Node, working in the same codebase, PR flow, and velocity as the rest of the v0 team.
• Show real security judgement across authentication and authorisation design, sandboxing and isolation, and injection vulnerability classes.
• Reason about an AI agent writing and running code as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title.
• Influence through code rather than process, fixing root causes in a PR instead of writing a policy doc, and act as the security conscience of a fast-moving team without becoming its bottleneck.
• Stay comfortable with ambiguity, since v0’s threat model is still being written and you will define it rather than inherit a mature playbook.
• Be willing to build with v0 rather than only secure it, using the product to understand how it works end to end.
🌟 Nice-to-have
• Already use v0 or be familiar with how it and Vercel's broader product line work.
• Have hands-on experience with sandboxing, container isolation, or multi-tenant systems.
• Have done prompt injection, jailbreak, or LLM application security research on an agentic or AI-powered product.
• Have shipped a coding agent, dev tool, or code-generation product end to end.
• Hold relevant security certifications such as OSCP or OSWE, or have a notable bug bounty or CTF history.
• Enjoy building content and talking publicly about your work through blog posts, conference talks, or research writeups.
🎯 Responsibilities
• Proactively hunt for vulnerabilities across v0, from code you're reviewing to systems you're actively poking at, and ship the fix rather than just the finding.
• Design and implement security-facing functionality as a normal part of the v0 roadmap, including sandboxing and isolation controls, permission boundaries, abuse detection, and safe defaults for generated apps.
• Act as security reviewer of record for everything the team ships, covering new capabilities, generated-app patterns, and integrations.
• Own the HackerOne relationship for v0, triaging and validating reports, driving fixes, and working directly with researchers on reproduction and remediation.
• Own and continuously refine the v0 threat model across sandbox and runtime isolation, permission boundaries between agent actions and user intent, and defences against prompt injection and tool-use abuse.
• Harden code execution boundaries, working on how agent-generated code is scoped, sandboxed, and constrained before it touches real infrastructure.
• Build guardrails that let v0 engineers ship new generated-app capabilities quickly without reintroducing known bug classes such as auth, SSRF, and injection.
• Partner with central Product Security on threat models, incident learnings, and SDLC tooling, while making the final call on v0-specific tradeoffs.
• Act as first responder and technical owner when a security issue is reported against v0.
• Think like an attacker and like an agent, reasoning about how a user or an agent acting on their behalf could misuse v0 to attack itself, other tenants, or the platform underneath it.
About Vercel
😃 What Vercel offers
• Receive a competitive compensation package including equity, with the San Francisco base range set at $208,000 to $312,000 and compensation outside San Francisco adjusted by location.
• Access an inclusive healthcare package.
• Learn and grow through mentorship and events that build your network and skills.
• Take flexible time off.
• Get the gear you need for the role plus a working from home budget to outfit your space.
💖 What makes Vercel unique
Vercel is the agentic infrastructure company, freeing people and agents to ship what comes next. For more than a decade it has shaped how the web is built, and as the team behind Next.js, v0, and the AI SDK it creates products that help builders move from idea to production with speed, security, and exceptional developer experience. Companies including OpenAI, PayPal, Ramp, and Supreme, along with millions of developers worldwide, build on the platform.
This position is no longer available, but we have other great opportunities!
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.