Security Software Engineer, Open Source Frameworks

Vercel - New York, United States

Hiring: Security Software Engineer, Open Source Frameworks Company: Vercel Location: New York, United States Job Posted Time: 2026-09-03 11:22:34 Target Skills & Keywords : JavaScript, Next.js, Node.js, Svelte, SvelteKit, TypeScript, Vercel About the job Experience: •4+ years in security engineering, ideally with real hands-on open source contribution experience. You've actually sent PRs to projects like these, not just filed issues against them. Required Skills: •Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be •Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro •. A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company. •Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues. •Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they're reported. •Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end. •Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel's open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers. •Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in. Qualifications: •You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them, and you treat that with the seriousness it deserves. You're not here to slow the project down with process for its own sake. •You're energized by root cause, not remediation count: Finding the one design flaw that kills fifty potential bugs is more satisfying to you than closing fifty tickets one at a time. •You can read framework internals, not just application code: Strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood (routing, SSR/RSC, middleware, bundling/build systems). •Pragmatic, not theoretical: You can weigh real-world risk against maintainer and community bandwidth, and land on security improvements that actually ship, rather than the theoretically ideal fix that never gets merged. •Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories. •Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike, in writing and in conversation. •Comfortable operating in public: You're used to working transparently with external researchers, maintainers, and the community, not just inside a company's four walls. •CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem. •Maintained or heavily contributed to a widely used open source project. •Thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance. Compensation: •$208,000 - $312,000 / year •Competitive compensation package, including equity Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!