Senior Product Security Engineer at Vercel focusing on product security initiatives across various platforms. Driving security-first culture while ensuring core infrastructure is secure and robust.
Responsibilities
Partner with engineering and product teams to perform threat modeling for new and existing features.
Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
Oversee Vercel’s open-source security efforts.
Evaluate, select, and integrate security tools into our Software Development Life Cycle.
Own and expand Vercel’s bug bounty program.
Lead and contribute to security projects that span multiple teams and disciplines.
Work closely with customer success and product marketing on security-related initiatives that impact our users.
Requirements
5+ years of experience in an Product Security or Product Security role (or related field), with a track record of securing web products and services.
Strong familiarity with JavaScript/TypeScript and Node.js runtime security.
Demonstrated ability to perform threat modeling and architectural risk analysis for complex product.
Hands-on experience with product security tooling such as static product security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration.
Knowledge of open-source security best practices.
Exposure to running or participating in a bug bounty program or vulnerability disclosure process.
Solid understanding of cloud architecture and serverless environments from a security perspective.
Proven ability to drive security initiatives and influence engineering teams to adopt best practices.
Benefits
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
Flexible Time Off.
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
Sales Executive responsible for developing new business opportunities for data security solutions in North America. Collaborating with sales and technical teams to drive and close sales in designated territory.
Assistant Vice President for Compliance in Global Human Resources at State Street. Engaging in regulatory change monitoring and compliance advisory support in a hybrid working model.
SOC Security Development Engineer developing security automation and SOC tooling for Binance. Join the Security Operations team focusing on engineering integration and incident response.
Legal or compliance professional handling regulatory changes for Global Human Resources at State Street. Engaging in compliance advisory and managing regulatory obligations across jurisdictions.
Student assistant supporting courses in IT forensics and AI security at Fraunhofer. Involvement in material development, PC exercises, and student interactions.
Safety Coordinator leading training and safety compliance initiatives at Constellium, a global aluminium transformation leader. Overseeing safety regulations, accident reporting, and trainings for personnel.
Lead security architecture and engineering function, driving secure innovation and operational excellence at Warner Bros. Discovery. Ensure compliance with regulatory frameworks and oversee a high - performing global team.
Senior Threat Detection & Response Engineer supporting federal cyber security programs. Overseeing design and development of countermeasures against cyber threats and advising on tools and training.
Manager of Security Advisors leading a sales - oriented team for acquiring security accounts. Driving growth through strategic prospecting and team management in a dynamic IT solutions environment.