Senior Product Security Engineer at Vercel focusing on product security initiatives across various platforms. Driving security-first culture while ensuring core infrastructure is secure and robust.
Responsibilities
Partner with engineering and product teams to perform threat modeling for new and existing features.
Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend.
Oversee Vercel’s open-source security efforts.
Evaluate, select, and integrate security tools into our Software Development Life Cycle.
Own and expand Vercel’s bug bounty program.
Lead and contribute to security projects that span multiple teams and disciplines.
Work closely with customer success and product marketing on security-related initiatives that impact our users.
Requirements
5+ years of experience in an Product Security or Product Security role (or related field), with a track record of securing web products and services.
Strong familiarity with JavaScript/TypeScript and Node.js runtime security.
Demonstrated ability to perform threat modeling and architectural risk analysis for complex product.
Hands-on experience with product security tooling such as static product security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration.
Knowledge of open-source security best practices.
Exposure to running or participating in a bug bounty program or vulnerability disclosure process.
Solid understanding of cloud architecture and serverless environments from a security perspective.
Proven ability to drive security initiatives and influence engineering teams to adopt best practices.
Benefits
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
Flexible Time Off.
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
Chargé.e d’Etudes et Travaux en systèmes électromécaniques de sécurité at RATP Infrastructures. Responsible for ensuring technical compliance and supervising project activities on - site.
Senior Infrastructure Security Engineer handling cloud security and infrastructure lifecycle for Zocks, a fintech startup. Responsible for security initiatives and compliance readiness in a rapidly growing team.
Data Center Security Officer ensuring safety and security for data center clients through patrols and monitoring. Conducting reports and maintaining client security requirements.
Cybersecurity Specialist overseeing the protection of clients' technology systems and networks. Implementing cybersecurity policies and conducting evaluations against cyber threats in a supportive working environment.
Senior Cybersecurity Incident Responder at ZEISS handling technical incident response activities. Collaborating with cyber defense teams to ensure effective incident management and resolution.
Information Security Manager responsible for steering InfoSec programs globally at ZEISS. Leading cross - functional initiatives and risk management strategies in a high - tech environment.
Providing security incident management for industrial environments at Telefónica Tech. Utilizing various monitoring platforms to enhance security posture.
Endpoint Security Engineer at Booz Allen designing and operationalizing data protection controls. Safeguarding sensitive data across enterprise systems and leading technical operations.
Senior Security Adviser handling governance and US integration tasks at Boeing. Liaising with US - based partners and coordinating crisis management for international security operations.