Senior Product Security Engineer at Vercel focusing on product security initiatives across various platforms. Driving security-first culture while ensuring core infrastructure is secure and robust.
Responsibilities
Partner with engineering and product teams to perform threat modeling for new and existing features.
Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
Oversee Vercel’s open-source security efforts.
Evaluate, select, and integrate security tools into our Software Development Life Cycle.
Own and expand Vercel’s bug bounty program.
Lead and contribute to security projects that span multiple teams and disciplines.
Work closely with customer success and product marketing on security-related initiatives that impact our users.
Requirements
5+ years of experience in an Product Security or Product Security role (or related field), with a track record of securing web products and services.
Strong familiarity with JavaScript/TypeScript and Node.js runtime security.
Demonstrated ability to perform threat modeling and architectural risk analysis for complex product.
Hands-on experience with product security tooling such as static product security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration.
Knowledge of open-source security best practices.
Exposure to running or participating in a bug bounty program or vulnerability disclosure process.
Solid understanding of cloud architecture and serverless environments from a security perspective.
Proven ability to drive security initiatives and influence engineering teams to adopt best practices.
Benefits
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
Flexible Time Off.
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
Security Architect for Logicalis focusing on networking and security solutions for clients. Engaging with vendors and providing technical documentation and proposals collaboratively.
Técnico de Segurança do Trabalho ensuring safety protocols and risk management at KFC stores in Brazil. Focused on implementing regulatory standards and safety training initiatives.
DevSecOps engineer at Ford ensuring secure software development and compliance with security standards. Collaborating with teams to embed security practices and assess vulnerabilities in software delivery.
Security Officer responsible for ensuring safety and security at the Genesee Brewing Company. Monitoring premises, responding to emergencies, and providing visitor assistance during shifts.
Security Estimator creating estimates and proposals for security projects at LINX. Collaborating with engineering and sales teams for system design and client relationships.
Product Security Architect at Expedia designing secure architecture for services and APIs. Collaborating with teams to guide secure practices and integrate AI - driven solutions.
IT Security Officer overseeing information security for a specific IT sector at Desjardins. Collaborating with cross - sector teams and managing information security risks and vulnerabilities.
Associate, Information Security professional at Santander focusing on Vulnerability Management and network security exposure. Collaborating with teams to enhance security posture and manage technology risks.
IAM Security & Technology Governance person driving IAM technical program with cutting - edge technology to improve security posture at MUFG. Manage IAM requirements, standards, governance and solutions across global implementation.
Senior Analyst in Mastercard's newly created Vocalink Control Office supporting control testing across Security domains. Ensuring a strong control environment and identifying gaps for improvement.