Security Engineer, Detection Response

Vercel · Hybrid - San Francisco, New York City, London, Berlin · Security · listed July 8, 2026

The shape of it

Seniority
Not stated
Where
Hybrid
Stated pay
$208,000 – $312,000
Requirements listed
8
Length
692 words

In the posting’s own words

We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing Vercel’s internal Corporate Security (CorpSec) posture, monitoring for security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibil i ty, and handle security incidents as they arise.

What it asks for · 8

  • Extensive experience in security operations, including SIEM management, security logging, and detection engineering.
  • Strong knowledge of AWS infrastructure and cloud security best practices.
  • Experience with GitHub administration and security controls.
  • Proficiency in SQL for data analysis and security investigations.
  • Hands-on experience with incident response, including detection, triage, and remediation.
  • Strong endpoint management skills across multiple operating systems (Mac, Windows, Linux).
  • Proficiency in at least one scripting language (Python, Bash) and one compiled language (Rust, Go).
  • Familiarity with serverless functions and API security is a plus.

Also a plus

  • Have experience working with managed SOC providers and security automation platforms.
  • Have worked in high-growth, cloud-native environments with a focus on scalability.
  • Are comfortable working in a fast-paced environment with shifting priorities.

What the job covers

  • Monitor and respond to security alerts across multiple channels, including managed SOC escalations.
  • Maintain visibility and logging infrastructure, ensuring effective SIEM (Security Information and Event Management) operations.
  • Support security audits for PCI, SOC2, ISO, and other compliance frameworks, gathering evidence and collaborating with Engineering, GRC and the broader Security Division.
  • Proactively enhance security operations by developing and deploying new detections, security tooling and rigorously managing key security partners.
  • Work on security investigations, incidents, and urgent requests as they arise, as well as contributing to the build-out and continuous improvement of the on-call process to enhance efficiency and effectiveness.
  • Continuously act as a guardian to enable the business to navigate risk-based changes.
  • Manage and enhance email security, endpoint security posture (EDR, configuration, and management), GitHub administration best practices, and internal security tooling to strengthen Vercel's overall security framework

Tools and skills named

Security & compliance
  • Security24×
  • PCI
  • SOC 2
Languages
  • Bash
  • Go
  • Python
  • Rust
  • SQL
Cloud & infra
  • AWS
  • Linux
  • Serverless
Operations & finance
  • Recruiting
Ways of working
  • On-call

Words the posting leans on

  • security24×
  • detection5×
  • experience4×
  • management4×
  • enhance3×
  • incidents3×
  • internal3×
  • arise2×
  • audits2×
  • distance2×
  • endpoint2×
  • engineering2×
  • ensuring2×
  • framework2×
  • github administration2×
  • infrastructure2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Vercel

every open role at Vercel

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Vercel on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.