Jobs and Careers
VE

Security Software Engineer, Open Source Frameworks

Vercel
- San Francisco, USAHybridfull_timePosted 18 Aug 2026

About the role

<div class="content-intro"><h2>About Vercel:</h2> <p><span data-sheets-root="1">Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.</span></p> <p><span data-sheets-root="1">For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.</span></p> <p><span data-sheets-root="1">Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.</span></p> <p><span data-sheets-root="1">We are building the platform for that future, trusted by companies like&nbsp;<strong>OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide</strong>. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.</span></p></div><h2>About the role</h2> <p>Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be <strong>Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro</strong>. A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company.</p> <p>We're looking for a security engineer who loves finding a whole class of vulnerability and eliminating it in one move, not someone who's satisfied filing one bug at a time. You'll run deep security assessments of framework internals (routing, middleware, caching, server actions, the build pipeline), find the systemic patterns that produce entire families of bugs, and drive the framework-level fixes and design changes that remove them permanently. You'll also own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. This includes hands-on ownership of Vercel's open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right maintainers.</p> <h2>What you will do</h2> <ul> <li><strong>Hunt for vulnerability classes, not individual bugs:</strong> Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues.</li> <li><strong>Drive root-cause framework fixes:</st

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Vercel

View company profile →