Role in brief
Vercel, known for Next.js, seeks a Product Security Engineer to embed security throughout their product development lifecycle. This role involves threat modeling, secure code reviews, and managing open-source security, ideal for an experienced engineer proficient in web technologies and security tooling.
About the role
This role focuses on integrating security into Vercel's product and platform development. The engineer will collaborate with product and engineering teams to conduct threat modeling for new features, identifying risks early and recommending solutions. A key part of the work involves performing secure code reviews on products built with Next.js and Node.js, ensuring the integrity of the codebase.
The position also entails overseeing Vercel's open-source security, which includes monitoring for vulnerabilities in third-party packages and coordinating their resolution. The engineer will evaluate and integrate security tools into the Software Development Life Cycle (SDLC) and manage the bug bounty program, triaging and validating vulnerability reports from external researchers.
Success in this role means driving security initiatives across the organization and contributing to projects that involve multiple teams. The engineer will also support customer-facing security efforts, working with customer success and product marketing to address user needs related to security. This ensures that security is not just an internal concern but also a visible and trusted aspect of Vercel's offerings.
The annual salary for this position ranges from $208,000 to $312,000 USD.
Skills that matter here
- JavaScript: Proficiency in JavaScript is required for conducting secure code reviews and understanding runtime security of web products.
- TypeScript: Familiarity with TypeScript is necessary for secure code reviews and analyzing web technology stacks.
- Node.js: Understanding Node.js runtime security is crucial for reviewing serverless backend components and services.
- Next.js: This role involves conducting security assessments on products and services built using Next.js.
- SAST: Hands-on experience with Static Application Security Testing (SAST) tools is needed for integrating security into the SDLC.
- DAST: Experience with Dynamic Application Security Testing (DAST) tools is required for evaluating and integrating security tooling.
Who this role suits
- An experienced security engineer with at least five years in product security or a related field.
- Someone who is adept at performing threat modeling and architectural risk analysis for complex products.
- An individual with a solid understanding of cloud architecture and serverless environments from a security perspective.
- A person capable of driving security initiatives and influencing engineering teams to adopt security best practices.
From the employer
What You Will Do:
- Threat Modeling & Design Review: Partner with engineering and product teams to perform threat modeling for new and existing features. Identify potential risks early in the design phase and recommend security controls or design changes to mitigate threats.
- Secure Code Review: Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
- Open Source Security Management: Oversee Vercel’s open-source security efforts, including monitoring and coordinating fixes for vulnerabilities in third-party open-source packages.
- SDLC Tooling & Automation: Evaluate, select, and integrate security tools into our Software Development Life Cycle.
- Bug Bounty Program Management: Own and expand Vercel’s bug bounty program, triaging and validating incoming vulnerability reports.
- Cross-Organizational Security Initiatives: Lead and contribute to security projects that span multiple teams and disciplines.
- Customer-Facing Security Support: Work closely with customer success and product marketing on security-related initiatives that impact our users.
About You:
- Experienced Security Engineer: 5+ years of experience in a Product Security or related role, with a track record of securing web products and services.
- Web Tech Stack Proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security.
- Threat Modeling & SDLC Expertise: Demonstrated ability to perform threat modeling and architectural risk analysis for complex products.
- Security Tools & Automation: Hands-on experience with product security tooling such as SAST, DAST, and CI/CD pipeline security integration.
- Open Source and Supply Chain Security: Knowledge of open-source security best practices.
- Bug Bounty & Vulnerability Management: Exposure to running or participating in a bug bounty program.
- Cloud & Serverless Security Understanding: Solid understanding of cloud architecture and serverless environments from a security perspective.
- Technical Leadership: Proven ability to drive security initiatives and influence engineering teams.
Benefits:
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - mentorship and events to build your network and skills.
- Flexible Time Off.
- WFH budget to outfit your space as needed.
Questions about this role
What is the remote work policy for this position?
This is a fully remote position, allowing work from various locations.
What is the seniority level for this role?
This position is for a middle-seniority level engineer.
What is the salary range for this role?
The salary for this role ranges from $208,000 to $312,000 USD annually.