Senior Security Software Engineer, v0

Vercel - New York, United States

Hiring: Senior Security Software Engineer, v0 Company: Vercel Location: New York, United States Job Posted Time: 2026-09-03 11:22:34 Employment Type: Full-time Target Skills & Keywords : Embedded Systems, LLM, Next.js, Node.js, REST, React, Serverless, TypeScript, Vercel About the job Experience: •5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior). You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role. Required Skills: •This role reports into the security organization but is deployed full-time with v0, and is evaluated as much on shipped product velocity as on security outcomes. As a senior (IC4) engineer, you're expected to operate independently, set the security bar for the team, and be trusted to make the final call on v0-specific tradeoffs. •Find and fix issues yourself: Proactively hunt for vulnerabilities across v0, from code you're reviewing to systems you're actively poking at, and ship the fix, not just the finding. •Build security features directly into the product: Design and implement the security-facing functionality itself (sandboxing/isolation controls, permission boundaries, abuse detection, safe defaults for generated apps) as a normal part of the v0 roadmap, not a side project. •Review all new v0 features and launches: Be the security reviewer of record for everything the team ships (new capabilities, generated-app patterns, integrations) before it goes out the door. •Own the HackerOne relationship for v0: Triage, validate, and drive fixes for reports from Vercel's HackerOne researcher community that touch v0, and work directly with researchers on reproduction and remediation. •Own the v0 threat model: Understand and continuously refine how v0 generates, executes, and deploys code, including sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool-use abuse. •Harden code execution boundaries: Work directly on how agent-generated code is scoped, sandboxed, and constrained before it touches real infrastructure, including Vercel's own sandbox and serverless runtimes. •Build guardrails that don't slow the team down: Create patterns, libraries, and checks that let v0 engineers ship new generated-app capabilities quickly without reintroducing known bug classes (auth, SSRF, injection) each time. Qualifications: •You're a software engineer first: 5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior). You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role. •Strong full-stack fundamentals: Comfortable in TypeScript, React, and Node, and able to work in the same codebase, PR flow, and velocity as the rest of the v0 team. •Real security judgment: You understand authN/authZ design, sandboxing and isolation, injection vulnerability classes, and can reason about "an AI agent writing and running code" as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title. •You influence through code, not just process: You'd rather fix the root cause in a PR than write a policy doc about it. You can be the security conscience of a fast-moving team without becoming its bottleneck. •Comfortable with ambiguity: v0's threat model is still being written. You're excited to define it rather than inherit a mature playbook. •Willing to build with v0, not just secure it: You're happy to actually go use v0 to build things and understand how our products work end to end, not just read the code from the outside. •Already a v0 user or familiar with how it and Vercel's broader product line work. •Applied hands-on capability in sandboxing, container isolation, or multi-tenant systems. •Done prompt injection / jailbreak / LLM application security research on an agentic or AI-powered product. •Previously shipped a coding agent, dev tool, or code-generation product end to end. Compensation: •$208,000 - $312,000 / year •Competitive compensation package, including equity Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!