Product Security Engineer
Vercel · Hybrid - San Francisco, New York City, London, Berlin · Security · listed June 26, 2026
The shape of it
Seniority
Not stated
Where
Hybrid
Stated pay
$208,000 – $312,000
Requirements listed
6
Length
1,220 words
In the posting’s own words
This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes.
What it asks for · 6
- You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for.
- Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale.
- Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet.
- Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you.
- Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook.
- Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks (ideally Next.js or React and Node-based frameworks), so you can read and validate the code your tooling is analyzing.
Also a plus
- Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
- Have experience running or triaging a bug bounty / vulnerability disclosure program.
- Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
- Have built systems that auto-generate or auto-propose code fixes, not just findings.
- Have thought about what security testing as a product capability could look like for a platform's customers.
- Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.
What the job covers
- Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match.
- Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures.
- Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in.
- Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place.
- Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them.
- Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one.
- Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform.
Tools and skills named
Security & compliance
- Security18×
- Penetration testing2×
- Threat modeling
Ways of working
- Testing7×
- Code review
Frameworks
- Node.js3×
- Next.js
- React
Languages
- JavaScript3×
- TypeScript
Models & research
- LLM2×
Operations & finance
- Recruiting
Product & design
- Design systems
Words the posting leans on
- security18×
- build11×
- triage11×
- tooling10×
- findings8×
- scale8×
- systems8×
- testing7×
- background6×
- bug bounty6×
- validate6×
- report5×
- engineer4×
- fix4×
- manual4×
- traditional4×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Vercel
- Account Executive, CommercialHybrid - London
- Account Executive, MajorsHybrid - London
- Account Executive, Majors (APAC)Hybrid - Sydney
- Account Executive, Majors- Install Base (APAC)Hybrid - Sydney
- Business Development Representative, MajorsHybrid - San Francisco, New York City, Austin
- Business Development Representative , StartupsHybrid - London