Skip to main content
CareerApp

Security Software Engineer, Open Source Frameworks

Vercel

Berlin, NY · Mid

$208,000 – $312,000

Listed on Vercel’s own careers site. You apply with them directly — we never stand between you and the employer.

What this role is

This role focuses on finding and eliminating classes of vulnerabilities across Vercel's open source web frameworks rather than patching individual bugs one at a time. It's ideal for a security engineer who understands modern JavaScript frameworks deeply, thrives on systemic fixes that protect millions of applications, and can work collaboratively with open source maintainers and the security community.

Our summary, not Vercel’s wording. The full posting is on their site.

Skills this role names

Log in to see which of these are already on your profile.

What they ask for

Required

  • 4+ years security engineering experience
  • Hands-on experience building with or finding security issues in Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro
  • Deep JavaScript/TypeScript fundamentals
  • Understanding of modern framework internals (routing, SSR/RSC, middleware, bundling)
  • Experience with structured security assessment methodology
  • Coordinated/responsible disclosure process experience
  • Clear written and verbal communication skills

Nice to have

  • CVE credits or published security research in JavaScript frameworks or Node ecosystem
  • Experience maintaining or heavily contributing to widely-used open source projects
  • Supply chain security tooling experience (Sigstore, SLSA, dependency scanning)
  • Prior bug bounty or vulnerability disclosure program experience
  • Consideration of AI-agent-authored code risks in open source contexts

Turn on analytics and we load Google Analytics: Google gets the pages you open and what you do here — searches, jobs you view, jobs you apply to — and sets its own cookies. Leave it off and the only cookies we set are your login, your theme, and this answer. Accept All also records a yes to advertising, which nothing uses yet. Privacy Policy.