# Security Software Engineer, Open Source Frameworks

Hiring organization: [Vercel](https://career.thegoodapps.co/organizations/vercel)

Canonical page: https://career.thegoodapps.co/jobs/7dc98577-205d-48f0-b2bd-c99b09c29275

Listed on Vercel's own careers site. Applications go to them directly.

- Seniority: Mid
- Location: Berlin, NY
- Salary: 208000 – 312000 USD per year

## Summary

This role focuses on finding and eliminating classes of vulnerabilities across Vercel's open source web frameworks rather than patching individual bugs one at a time. It's ideal for a security engineer who understands modern JavaScript frameworks deeply, thrives on systemic fixes that protect millions of applications, and can work collaboratively with open source maintainers and the security community.

_Our summary, not Vercel's wording._

## Skills named

JavaScript, Nuxt.js, Svelte, SvelteKit, TypeScript

## Required

- 4+ years security engineering experience
- Hands-on experience building with or finding security issues in Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro
- Deep JavaScript/TypeScript fundamentals
- Understanding of modern framework internals (routing, SSR/RSC, middleware, bundling)
- Experience with structured security assessment methodology
- Coordinated/responsible disclosure process experience
- Clear written and verbal communication skills

## Nice to have

- CVE credits or published security research in JavaScript frameworks or Node ecosystem
- Experience maintaining or heavily contributing to widely-used open source projects
- Supply chain security tooling experience (Sigstore, SLSA, dependency scanning)
- Prior bug bounty or vulnerability disclosure program experience
- Consideration of AI-agent-authored code risks in open source contexts

Apply on Vercel's site: https://job-boards.greenhouse.io/vercel/jobs/6117204004
