Security Software Engineer, Open Source Frameworks
Job description
About the role
Vercel is seeking a security specialist to protect the foundational frameworks that power the modern web. You will focus on eliminating entire classes of vulnerabilities within projects like Turborepo, Nuxt, Svelte, SWR, Workflow, and Nitro by improving their core architecture. In this role, you will act as the primary security architect for some of the most widely adopted tools in the JavaScript ecosystem. You will own the security posture of the frameworks from the design phase through to production deployment and public disclosure. Your work will directly impact the safety of thousands of applications and millions of users worldwide. You will translate complex security risks into actionable guidance for both technical and non-technical stakeholders. This position requires a proactive mindset to identify threats before they can be exploited in the wild.
Key facts
What you'll do
- Perform deep security assessments on framework internals, including routing, middleware, caching, and build pipelines to uncover hidden attack surfaces.
- Implement upstream design changes that resolve systemic security flaws across all applications using these frameworks, ensuring fixes scale universally.
- Manage the end-to-end vulnerability disclosure process, including CVE issuance, tracking, and the publication of public advisories with clear mitigation steps.
- Operate the open source bug bounty program by triaging incoming reports, validating findings, and coordinating timely fixes with project maintainers.
- Integrate security into the design phase of new features by actively participating in RFCs, architecture reviews, and threat modeling sessions.
- Develop preventive security tooling such as custom linters, automated codemods, and enhanced CI checks to catch regressions before merge.
- Strengthen supply chain security for package distribution, focusing on artifact signing, provenance verification, and dependency integrity checks.
- Collaborate transparently with the open source community, external security researchers, and core maintainers to build trust and ensure responsible disclosure.
- Analyze production telemetry and real-world exploit patterns to prioritize security initiatives based on actual risk impact.
- Mentor junior engineers on secure coding practices and threat modeling techniques within the context of web framework development.
- Contribute to the evolution of security standards specific to meta-frameworks by documenting best practices and reference implementations.
- Lead incident response efforts for security vulnerabilities discovered in the Vercel open source portfolio, ensuring minimal customer disruption.
- Evaluate emerging attack vectors such as server-side request forgery and dependency confusion within the specific context of modern JavaScript toolchains.
- Drive the adoption of secure defaults across all framework configurations to reduce the burden on application developers.
Requirements
- 4+ years of professional experience in security engineering, with a proven track record of identifying and resolving complex vulnerabilities.
- Direct experience building with or identifying security flaws in Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro, demonstrating a practical understanding of their ecosystems.
- Strong proficiency in JavaScript and TypeScript, coupled with a deep understanding of meta-framework internals like SSR, RSC, and intricate build systems.
- Demonstrated ability to perform structured security assessments, including threat modeling, static analysis, and dynamic testing methodologies.
- Proven skill in managing coordinated disclosure processes with multiple stakeholders, maintaining clear communication under pressure.
- Exceptional written and verbal communication skills to articulate complex security tradeoffs to both maintainers and non-security engineers effectively.
- A history of meaningful contributions to open source projects, evidenced by merged pull requests and sustained engagement with upstream communities.
- Familiarity with secure software development lifecycle practices and the ability to integrate security gates into existing workflows.
- Commitment to responsible disclosure principles and the ethical handling of sensitive vulnerability data.
- Ability to work asynchronously in a distributed team environment across multiple time zones while maintaining alignment on critical objectives.
- Willingness to travel occasionally to meet with open source contributors, partners, and security researchers in key locations.
- Capacity to balance high-priority security incidents with long-term strategic improvements to the framework security posture.
- Understanding of secure coding practices specific to Node.js runtime environments and the npm/yarn/pnpm package ecosystems.
- Dedication to maintaining and enhancing the security documentation for internal tools and public-facing advisories.
Nice to have
- Published security research or CVE credits, particularly within the Node.js or JavaScript framework ecosystems, that demonstrate a history of impactful discoveries.
- History of maintaining or significantly contributing to widely used open source software, showing the ability to manage complex codebases and community expectations.
- Expertise in supply chain security tools such as Sigstore or SLSA, including implementation of signing and verification workflows.
- Experience managing bug bounty programs, including platform administration, payout coordination, and researcher relationship management.
- Perspective on the security implications of AI-agent-generated code contributions, including the ability to assess risks introduced by large language model tooling.
Skills & tools
JavaScript, TypeScript, Node.js, Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, Sigstore, SLSA.
Practical notes
- Compensation includes a competitive salary, equity, and benefits.
- The base pay range for San Francisco is $208,000 to $312,000, with adjustments based on location and experience.
- Benefits include an inclusive healthcare package, flexible time off, mentorship opportunities, and a remote work stipend.
- This is a full-time position with hybrid work options available in San Francisco, New York City, London, and Berlin.
- Willingness to travel occasionally is required to engage with the open source community and research partners.
- The role involves on-call responsibilities for critical security incidents affecting the framework supply chain.
- All applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, or age.