Senior Security Software Engineer, v0
Job description
About the role
Vercel is seeking a Senior (IC4) Software Engineer to join the v0 team as a dedicated security lead. You will function as a peer engineer, balancing feature development with the responsibility of securing an AI-driven environment that generates and executes code. In this capacity, you will own the security posture of the v0 platform end to end, ensuring that safety mechanisms are integral rather than incidental. You will partner closely with product and design to embed security into the user journey without compromising the rapid development ethos of the team. The role requires you to translate ambiguous risk into actionable engineering tasks while mentoring engineers on secure coding practices. You will act as the final gatekeeper for production releases, applying threat intelligence to defend against emerging attack vectors. This position is critical for maintaining trust with our user base who rely on v0 to handle sensitive code execution safely.
Key facts
What you'll do
- Investigate and triage security findings in the v0 codebase to identify root causes and implement robust fixes.
- Architect and implement isolation controls that enforce strict boundaries between user sessions and execution contexts.
- Design and deploy permission boundaries that enforce least privilege access across the v0 feature set.
- Engineer abuse prevention mechanisms to stop automated attacks and resource exhaustion attempts.
- Lead security reviews for every new product launch and third-party feature integration before launch.
- Operate and evolve the v0 HackerOne program, managing researcher submissions and driving timely remediation.
- Analyze and update the v0 threat model with a specific focus on sandbox escape risks and runtime isolation failures.
- Implement infrastructure hardening measures that reinforce the integrity of the execution pipeline.
- Build and maintain reusable security libraries and design patterns that prevent entire classes of vulnerabilities.
- Partner with the central Product Security team during incident response and the development of SDLC security tooling.
- Define secure coding standards for the v0 stack and enforce them through automated checks and code reviews.
- Conduct threat modeling sessions to identify risks early in the design phase of new features.
- Create security validation tests that ensure isolation and permission controls remain effective over time.
- Communicate security risks and mitigations clearly to both technical and non-technical stakeholders.
Requirements
- Bring 5+ years of professional software engineering experience focused on building and shipping production web applications.
- Demonstrate advanced proficiency in TypeScript, React, and Node.js with a proven track record of production deployments.
- Exhibit a deep understanding of authentication and authorization mechanisms and their limitations.
- Show mastery of sandboxing concepts and the ability to analyze runtime isolation boundaries critically.
- Display comprehensive knowledge of common injection vulnerabilities including SQLi, XSS, and command injection.
- Operate effectively as an IC4-level engineer capable of making impactful decisions with minimal supervision.
- Prioritize security outcomes rigorously while maintaining the high product velocity expected of the v0 team.
- Engage directly with the v0 product as an active user to develop an intuitive understanding of its internal mechanics.
- Apply security principles consistently across the software development lifecycle from design through deployment.
- Maintain curiosity about adversarial techniques and a proactive mindset for discovering potential attack paths.
Nice to have
- Hands-on experience with container isolation technologies and securing multi-tenant architectures.
- Research background in LLM security, prompt injection mitigation, or techniques used in jailbreaking scenarios.
- History of building developer tools, CLIs, or code-generation products that impact developer workflows.
- Possession of relevant certifications such as OSCP or OSWE, or a documented history of bug bounty program participation.
- Interest in contributing to public-facing security work such as technical blogging or presenting at industry conferences.
Practical notes
- Full-time engagement is required for this position.
- Compensation includes equity, an inclusive healthcare package, flexible time off, and a work-from-home stipend.
- The company provides necessary hardware and supports professional growth through mentorship and events.
- Vercel is an equal opportunity employer and encourages applications even if you do not meet every listed qualification.
This role is based in hybrid locations including San Francisco, New York City, London, and Berlin providing flexibility while fostering in-person collaboration. The successful candidate will be expected to attend periodic team gatherings to align on strategy and share security insights. Travel requirements are minimal but may be requested for team events or security briefings as dictated by business needs. Employment is contingent upon the completion of standard background checks if required by role and location. The application process will move at a pace that respects the urgency of securing our critical infrastructure while ensuring thorough evaluation of each candidate.