Product Security Engineer
$208k - $312kVercel Corp
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what's next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you're building our products, supporting our customers, growing our community, or shaping our story, you'll help define what comes next. About the Role: Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does. This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes. More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel's own surface. Because of this, we're optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we're looking for. If you're based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.
What You Will Do:
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description. The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
What You Will Do:
- Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match.
- Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures.
- Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in.
- Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place.
- Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them.
- Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one.
- Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform.
- You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for.
- Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale.
- Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet.
- Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you.
- Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook.
- Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks (ideally Next.js or React and Node-based frameworks), so you can read and validate the code your tooling is analyzing.
- Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
- Have experience running or triaging a bug bounty / vulnerability disclosure program.
- Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
- Have built systems that auto-generate or auto-propose code fixes, not just findings.
- Have thought about what security testing as a product capability could look like for a platform's customers.
- Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description. The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Product Security Engineer in San Francisco, CA vacancy
- ...$250+ million raised to date. About the Role Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering...Suggested
$227k - $296k
...deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprises. We're hiring a...SuggestedFull timeWork at officeWork from homeVisa sponsorshipRelocation packageFlexible hours- ...tenant isolation, and the blast radius of a single agent action product design questions, and it puts product security on the critical path of every enterprise deal we close. We are looking for the engineer who owns that. This is a hands-on role and the first dedicated...SuggestedWork at officeFlexible hours
$175k - $215k
...and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures...SuggestedTemporary work$250k - $285k
...Staff Product Security Engineer Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens...SuggestedTemporary work- ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on DataRobot... ...the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform meets...Full timeLocal areaRemote workWorldwideFlexible hours
- ...Staff Product Security Engineer Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Navan, Qantas...Worldwide
$220k - $330k
...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We're... ...getting started. Role Overview As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how...Work experience placement- The Opportunity Are you passionate about securing global systems and mitigating risks in a fast-paced environment? Adobe Security... ...its Vulnerability Operation Center (VOC). As a VOC Senior Product Security Engineer, you will analyze and triage incoming identified...
$130k - $215k
Product Security Engineer Astranis builds advanced satellites for high orbits, expanding humanity's reach into the solar system. Today, Astranis satellites provide dedicated, secure networks to highly-sophisticated customers across the globe— large enterprises, sovereign...Permanent employmentFlexible hours$235k - $275k
Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00...Full time- ...Responsibilities Own and operate a scalable secure software development lifecycle covering... ..., and scanning. Partner with engineering on security features and secure-by-design... ...analysis, secret scanning, and SAST across product repositories. Mentor engineers and...Full time
$188k - $282k
...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re... ...re just getting started.Role OverviewAs a Senior Software Engineer on the Product Security team at Harvey, you'll be a key technical contributor...Flexible hours$180k - $258k
...Curious to learn more about our story? Check out this blog post written by our founders. Role OverviewWe are looking for a Product Security Engineer to join our team and act as a champion for security within our product engineering organization. You will be responsible...Shift work$180k - $247k
Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building the... ...re building a world where Identity belongs to you.The Staff Product Security Engineer OpportunityThe Security team's mission is to strengthen Okta...Local areaWorldwideFlexible hours- ...communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security challenges, but our...Work at officeRelocation3 days per week1 day per week
- ...60k - $225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A funding, and...Full time
$200k - $220k
...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting... ...tooling across macOS and enterprise environments. Write production-quality scripts and automation in Python or Bash, and have...Local area- ...work with AI. About the Role This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the... ...platform by conducting threat modeling sessions with product teams, designing secure architectures for new...Full timeWork at officeLocal areaFlexible hours
- ...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial... ...OpenAI's technology, people, and products. We are technical in what we build but are... .... About the Role As a Security Engineer, Application Security you will be responsible...Work at officeRemote workRelocation package
- ...The Endpoint Security & Exposure Management Engineer is responsible for the design, implementation, administration, and continuous improvement of endpoint security controls and enterprise exposure management capabilities. This role focuses on reducing organizational cyber...
$10 per hour
...Security Engineer, Corporate Security San Francisco, California, United States About Flexport At Flexport, we believe global trade can move the human race forward. That's why it's our mission to make global commerce so easy there will be more of it. We're shaping...Work at officeImmediate startRelocationRelocation packageFlexible hours- ...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers... ...-by-default experiences that actually make people more productive, this is the team to join. About the Role: As a Senior...For contractorsRemote work
- ...experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a... ...New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org...Full timeWork experience placementLocal area
- ...Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team. Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the...Full timeWork experience placementWork at officeRemote work
- ...Responsibilities Support secure code reviews, architecture reviews, threat modeling, and the security review program.... ...bounty, and responsible disclosure activities. Partner with engineering and product teams to embed secure-by-design practices and security tooling...Full time
- ...Responsibilities Embed security review workflows and PR-level analysis into the software... ...and guardrails for more than 50 engineers. Create threat models for new features... ...Find and fix real vulnerabilities in production applications rather than only running scanners...Full timeWork at officeRemote workRelocation package
$300k - $320k
...Perform penetration testing of specific, high-value deployments. Contribute to AI-assisted security testing tools and workflows. Collaborate with security and engineering teams on AI-specific attack scenarios. Document and present findings to technical and...Full timeWork at officeVisa sponsorshipFlexible hours$128.9k - $180k
...we can’t wait to meet you. WHAT YOU'LL DO As a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees... ...infrastructure operating at the center of cloud operations, product, app security, and system architecture. That includes developing...Full timeWork at officeFlexible hours- ...a Senior Backend or Full-Stack Software Engineer (5+ years experience) who wants to build... ...healthcare delivery. At Sprinter, you’ll work on products that blend logistics, patient experience... ..., and medical devices in a reliable, secure way Work closely with product, data,...Full timeTemporary workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Engineer. Be the first to apply!
Related searches
- cad design engineer solidworks San Francisco, CA
- product engineering manager San Francisco, CA
- staff design engineer San Francisco, CA
- sr. product engineer San Francisco, CA
- design engineer San Francisco, CA
- director of product engineering San Francisco, CA
- design assurance engineer San Francisco, CA
- product design engineer San Francisco, CA
- senior software design engineer San Francisco, CA
- digital design engineer San Francisco, CA




