Security Software Engineer, Open Source Frameworks
Vercel · Hybrid - San Francisco, New York City, London, Berlin
Posted about 2 months ago · $208,000.00 - $312,000.00
or apply directly on Vercel's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 55 days Vercel's roles stay open a median of 56 days
- Reposted
- No
- Salary listed
- Yes 79% of Vercel's roles list one
- Ghost-job risk at Vercel
- high 74 stale, 3 reposted of 91 open
- Hiring momentum
- 109 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-28
Measured from postings appearing on and disappearing from Vercel's own greenhouse board since 2026-08-03. Full hiring picture for Vercel.
About this role
The Security Software Engineer role at Vercel focuses on enhancing the security of open source frameworks like Turborepo, Nuxt, and Svelte. The engineer will conduct deep security assessments, drive framework-level fixes, manage vulnerability disclosures, and oversee the open source bug bounty program. This position emphasizes proactive security measures and collaboration with the open source community to ensure robust security practices are integrated from the design phase.
- benefits
- 3/5
- freshness
- 1/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 5/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Vercel as an employer.
What you need
- Experience with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro
- 4+ years in security engineering with hands-on open source contribution experience
- Strong JavaScript/TypeScript fundamentals
- Experience with structured security assessment methodology and coordinated disclosure processes
- Ability to communicate vulnerabilities and design recommendations clearly
- Comfortable working transparently with external researchers and the community
Nice to have
- CVE credits or published security research in JavaScript frameworks or the Node ecosystem
- Experience with supply chain security tooling
- Experience running or triaging a bug bounty program for open source projects
What you get
- Competitive compensation package, including equity
- Inclusive Healthcare Package
- Mentorship and opportunities to attend events for skill building
- Flexible Time Off
- Provision of necessary gear and a WFH budget
Worth weighing
- No specific mention of remote work policy beyond hybrid locations
- Salary range provided only for San Francisco, with adjustments based on location
- Emphasis on community engagement may require significant public interaction
Summarised from Vercel's posting. Read the full original.
Listed by Vercel on their greenhouse job board, last confirmed open on 2026-09-28. PitchMeAI is not the employer.
More roles at Vercel
- Software Engineer, CDN ContentHybrid - San Francisco
- Technical Account ManagerHybrid - London, Berlin
- Senior Security Software Engineer, v0Hybrid - San Francisco, New York City, London, Berlin
- Solutions ArchitectHybrid - San Francisco, New York City, Austin
- Product Communications ManagerHybrid - San Francisco
- Product Security EngineerHybrid - San Francisco, New York City, London, Berlin
- Sales Development Representative, UK&IHybrid - London
- Product Strategy & OperationsHybrid - San Francisco