Security Engineer, Cloud

Remote $208k–$312k middle 1 month ago full-time quality 8.6/10

Role in brief

Vercel, known for Next.js, seeks a Security Engineer to secure its cloud-native platform. This role involves designing and implementing security controls, hardening infrastructure, and integrating security best practices. Ideal for experienced security professionals with a strong background in AWS/GCP, infrastructure-as-code, and CI/CD security, who can balance engineering needs with security principles.

AWSGCPTerraformCDKKubernetesCI/CD

About the role

This role focuses on strengthening the security posture of Vercel's cloud-native platform. The Security Engineer will be responsible for designing and implementing scalable security controls, hardening infrastructure components using tools like Terraform and Kubernetes, and building secure CI/CD pipelines. This involves ensuring that the platform, which supports products like Next.js and v0, remains robust and protected as it scales.

A key aspect of this position is collaboration with platform and infrastructure teams. The engineer will integrate security best practices into existing architectures and workflows, driving improvements in monitoring, detection, and incident response. This requires staying current with cloud security trends and adopting new technologies to enhance the platform's overall resilience against threats.

Success in this role means consistently shipping secure and resilient systems at scale. The engineer will conduct threat modeling, risk analysis, and mitigation planning for critical systems, while also building and maintaining relevant security tooling. The goal is to create a secure-by-default environment that supports Vercel's mission to enable developers to move from idea to production with speed and security.

The base salary for this role ranges from $208,000 to $312,000, with actual pay based on skills, experience, and location.

Skills that matter here

  • AWS: This role requires a deep understanding of securing cloud infrastructure within AWS environments.
  • GCP: The engineer will apply their expertise in securing cloud infrastructure within GCP environments.
  • Terraform: The role involves hardening infrastructure components using Terraform for infrastructure-as-code.
  • CDK: The engineer will utilize CDK to harden infrastructure components and implement security controls.
  • Kubernetes: Proficiency in Kubernetes is essential for securing containerized environments and infrastructure.
  • CI/CD: The role requires building secure infrastructure and code within CI/CD pipelines and ensuring their security.

Who this role suits

  • You have a proven track record of shipping secure, resilient systems at scale.
  • You are skilled at balancing engineering realities with principled security practices.
  • You have 8+ years of experience in infrastructure or platform security roles.
  • You are proactive in staying ahead of cloud security trends and adopting cutting-edge technologies.

From the employer

What you will do:

  • Design and implement scalable security controls across our cloud-native platform.
  • Harden infrastructure components using infrastructure-as-code, policy enforcement, and service isolation.
  • Build secure by default infrastructure and code CI/CD pipelines.
  • Collaborate with platform and infrastructure teams to integrate security best practices into architecture and workflows.
  • Stay ahead of cloud security trends and adopt cutting-edge technologies to enhance platform resilience.
  • Conduct threat modeling, risk analysis, and mitigation planning for critical systems.
  • Drive improvements in monitoring, detection, and incident response at the platform level.
  • Build, deploy and maintain relevant tooling.

About you:

  • 8+ years of experience in infrastructure or platform security roles.
  • Deep understanding of secure cloud infrastructure (AWS/GCP), identity and access management, and system hardening.
  • Proficient with tools like Terraform, CDK, Kubernetes, and CI/CD security.
  • Skilled at balancing engineering realities with principled security practices.
  • Proven track record of shipping secure, resilient systems at scale.

Bonus if you:

  • Have built or scaled security automation pipelines.
  • Contributed to open-source security projects or tools.
  • Hold certifications such as GCP Security Engineer, AWS certifications, CISSP, or OSCP.
  • Hold a bachelors or masters degree in Cybersecurity or similar disciplines.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
  • The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. This salary range is an estimate. Actual salary will be based on job related skills, experience and location. Pay ranges outside San Francisco may be adjusted based on employee location. The total compensation package also includes benefits and equity-based compensation.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What level of seniority is expected for this position?

This is a middle-seniority role, requiring 8+ years of experience in relevant security roles.

What are the key technical skills required for this role?

Candidates should have a deep understanding of AWS/GCP, identity and access management, system hardening, and be proficient with tools like Terraform, CDK, Kubernetes, and CI/CD security.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Vercel.