Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Product Security Engineer

$208k - $312k

Vercel Corp

About Vercel:

Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. For more than a decade we've helped builders move from idea to production with speed, security, and exceptional developer experience.

Now we're scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.

About the Role:

Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does.

This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes.

More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel's own surface.

Because of this, we're optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we're looking for.

If you're based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:

  • Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match.
  • Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures.
  • Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in.
  • Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place.
  • Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them.
  • Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one.
  • Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform.

About You:

  • You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for.
  • Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale.
  • Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet.
  • Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you.
  • Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook.
  • Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks (ideally Next.js or React and Node-based frameworks), so you can read and validate the code your tooling is analyzing.

Bonus If You:

  • Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
  • Have experience running or triaging a bug bounty / vulnerability disclosure program.
  • Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
  • Have built systems that auto-generate or auto-propose code fixes, not just findings.
  • Have thought about what security testing as a product capability could look like for a platform's customers.
  • Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.

Compensation & Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

Disclosures:

  • Privacy: Please review our Job Applicant Privacy Policy for more information on how we handle your data.
  • Equal Opportunity: Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Product Security Engineer in San Francisco, CA vacancy
  • $180k - $258k

     ...infrastructure from the ground up.Our core product is an autonomous Revenue Cycle Management...  ...by AI agents and a configurable rules engine, the platform unifies clinical, billing,...  ...Role OverviewWe are looking for a Product Security Engineer to join our team and act as a champion... 
    Suggested
    Shift work

    Candid Health

    San Francisco, CA
    2 days ago
  • $117.2k - $176.7k

     ...the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.Job Title: Product Security Engineer, InfrastructureJob Category: Technology / SecurityLocation: San Francisco, CA or Bellevue, WAThe ExperienceJoin our... 
    Suggested
    Full time

    Salesforce

    San Francisco, CA
    3 days ago
  • $208k - $312k

     ...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.Now,...  ...background is manual penetration testing. A software engineer with a strong desire to move into security,... 
    Suggested
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel

    San Francisco, CA
    2 days ago
  • $188k - $282k

     ...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re...  ...re just getting started.Role OverviewAs a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity to build... 
    Suggested
    Work experience placement
    Flexible hours

    Harvey

    San Francisco, CA
    4 days ago
  • $160k - $250k

     ...financial operations or build and monetize financial products of their own.We started in Melbourne in 2015 to build...  ...see it in full.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data... 
    Suggested
    Temporary work
    Local area

    Airwallex

    San Francisco, CA
    4 days ago
  • $175k - $215k

     ...and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures... 
    Temporary work

    Crusoe

    San Francisco, CA
    1 day ago
  •  ...tenant isolation, and the blast radius of a single agent action product design questions, and it puts product security on the critical path of every enterprise deal we close. We are looking for the engineer who owns that. This is a hands-on role and the first dedicated... 
    Work at office
    Flexible hours

    BackOps AI

    San Francisco, CA
    1 day ago
  • $227k - $296k

     ...deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprises. We're hiring a... 
    Full time
    Work at office
    Work from home
    Visa sponsorship
    Relocation package
    Flexible hours

    Apollo Research

    San Francisco, CA
    2 days ago
  •  ...Senior Product Security Engineer At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray, a popular open-source project that's creating an ecosystem of libraries... 
    Flexible hours

    Anyscale

    San Francisco, CA
    4 days ago
  •  ...Application Security Engineer Retool handles our customers' most sensitive data and provides a platform where they write and execute arbitrary...  ...rather than the exception. You'll need to understand the product deeply to secure it well: what customers build on Retool,... 
    Shift work

    Retool

    San Francisco, CA
    5 days ago
  •  ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on DataRobot...  ...in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform meets... 
    Full time
    Local area
    Remote work
    Worldwide
    Flexible hours

    DataRobot

    San Francisco, CA
    3 days ago
  • $172.5k - $313.7k

     ...right place! Agentforce is the future of AI, and you are the future of Salesforce.Job Title: Principal Engineer, Product SecurityThe ExperienceThe Product Security team sits within Trust & Security, partnering closely with engineering across Salesforce's fastest-growing... 
    Full time

    Salesforce

    San Francisco, CA
    4 days ago
  •  ...communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security challenges, but our... 
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    San Francisco, CA
    3 days ago
  • $250k - $285k

     ...of a high-performing team that believes in each other, come build with us at Crusoe.About This RoleWe’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and distributed... 
    Temporary work

    Crusoe

    San Francisco, CA
    1 day ago
  •  ...identity verification infrastructure where security isn't a layer we add later, it's core to...  .... As AI tooling expands what engineers can build and how fast they can build it...  ...that scale security across every team and product. Partner with product engineers to shape... 
    Full time
    For contractors
    Internship
    Relocation package

    Persona

    San Francisco, CA
    4 days ago
  • $231.9k - $318.25k

     ...Work as a hands-on Product Security Engineer to make secure outcomes the default across the codebase and delivery workflow. Responsibilities Identify systemic security gaps in the codebase and engineering workflows, then partner with engineering teams to design and... 

    Cybersecurity Jobs

    San Francisco, CA
    3 days ago
  •  ...Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and... 
    Full time

    Zof AI

    San Francisco, CA
    4 days ago
  • $172.5k - $313.7k

     ...world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.**Job Title:** Principal Engineer, Product Security**The Experience**The Product Security team sits within Trust & Security, partnering closely with engineering across... 

    Jobleads-US

    San Francisco, CA
    3 days ago
  • $50 per hour

     ...computational biology. About This Role Crusoe Security & Compliance is hiring a Senior/Staff Application Security Engineer to play a critical role in ensuring the...  ...improvement of our security posture, making our products safer and our customers' data more secure.... 
    Temporary work

    ProducePay

    San Francisco, CA
    1 day ago
  • $107.4k - $155.7k

    Software Product Security Engineer - HP IQDescription -About the RoleAs a Software Engineer specializing in Device Security, you will contribute to building secure, privacy-focused technologies for HP IQ's next generation of AI-enabled devices. You’ll work alongside experienced... 
    Full time
    Temporary work
    Local area
    Relocation
    Flexible hours
    Shift work

    Juniper Networks

    San Francisco, CA
    2 days ago
  •  ...60k - $225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A funding, and... 
    Full time

    Motion Recruitment

    San Francisco, CA
    4 days ago
  • $235k - $275k

    Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00... 
    Full time

    Code Red Partners

    San Francisco, CA
    1 day ago
  • $134.5k - $265.1k

     ...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection...  ...to deal shaping, influencing product direction, and providing appropriate support...  ...cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    3 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    San Francisco, CA
    5 days ago
  • $266k

     ...general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are...  ...robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for... 
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    5 days ago
  • $10 per hour

     ...impact business, society, and the environment? Come join us.All security disciplines work under the umbrella of the combined PSI (...  ...Infrastructure) team: we build the paved path and tooling that hundreds of engineers around the world rely on every day to ship. Corporate Security... 
    Work at office
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    San Francisco, CA
    3 days ago
  • $200k - $220k

     ...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our...  ...detection tooling across macOS and enterprise environments.Write production-quality scripts and automation in Python or Bash, and have... 
    Work at office
    Local area

    Notion Labs

    San Francisco, CA
    1 day ago
  • $183k - $247.6k

     ...communities around the world.We are a specialized security team that sits inside a global satellite...  ...designing, launching, and operating the product, and we partner closely with incident...  ...Experience in threat hunting, detection engineering, or product/application security,... 
    Permanent employment
    Local area
    Immediate start
    Flexible hours
    Shift work

    Amazon

    San Francisco, CA
    4 days ago
  •  ...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers...  ...-by-default experiences that actually make people more productive, this is the team to join. About the Role: As a Senior... 
    For contractors
    Remote work

    CoreWeave

    San Francisco, CA
    4 days ago
  •  ...Application Security Engineer Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company...  ...For ~ You've found and fixed real vulnerabilities in production applications - not just run scanners ~ Deep understanding... 
    Work at office
    Remote work
    Relocation package
    Shift work

    Mercor Inc

    San Francisco, CA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Product Security Engineer. Be the first to apply!