Senior · Гибрид · Сан-Франциско, США · Английский B2
Навыки
LLM
Next.js
Ответственность за результат
React
REST API
Роадмап
Жизненный цикл разработки
Ещё 1
TypeScript
О компании и продукте
Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.
Задачи
Find and fix issues yourself: Proactively hunt for vulnerabilities across v0, from code you're reviewing to systems you're actively poking at, and ship the fix, not just the finding
Build security features directly into the product: Design and implement the security-facing functionality itself (sandboxing/isolation controls, permission boundaries, abuse detection, safe defaults for generated apps) as a normal part of the v0 roadmap, not a side project
Review all new v0 features and launches: Be the security reviewer of record for everything the team ships (new capabilities, generated-app patterns, integrations) before it goes out the door
Own the HackerOne relationship for v0: Triage, validate, and drive fixes for reports from Vercel's HackerOne researcher community that touch v0, and work directly with researchers on reproduction and remediation
Own the v0 threat model: Understand and continuously refine how v0 generates, executes, and deploys code, including sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool-use abuse
Harden code execution boundaries: Work directly on how agent-generated code is scoped, sandboxed, and constrained before it touches real infrastructure, including Vercel's own sandbox and serverless runtimes
Build guardrails that don't slow the team down: Create patterns, libraries, and checks that let v0 engineers ship new generated-app capabilities quickly without reintroducing known bug classes (auth, SSRF, injection) each time
Partner with central Product Security: Share threat models, incident learnings, and SDLC tooling with the broader security team, while making the final call on v0-specific tradeoffs since you have the deepest context on the product
Respond to v0-specific security reports and incidents: Be the first responder and technical owner when a security issue is reported against v0 specifically
Think like an attacker, and like an agent: Reason about how a user, or an agent acting on that user's behalf, could misuse v0 to attack itself, other tenants, or the platform underneath it
Требования
You're a software engineer first: 5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior)
You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role
Strong full-stack fundamentals: Comfortable in TypeScript, React, and Node, and able to work in the same codebase, PR flow, and velocity as the rest of the v0 team
Real security judgment: You understand authN/authZ design, sandboxing and isolation, injection vulnerability classes, and can reason about "an AI agent writing and running code" as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title
You influence through code, not just process: You'd rather fix the root cause in a PR than write a policy doc about it
You can be the security conscience of a fast-moving team without becoming its bottleneck
Comfortable with ambiguity: v0's threat model is still being written. You're excited to define it rather than inherit a mature playbook
Willing to build with v0, not just secure it: You're happy to actually go use v0 to build things and understand how our products work end to end, not just read the code from the outside
Bonus if you have
Already a v0 user or familiar with how it and Vercel's broader product line work
Hands-on experience with sandboxing, container isolation, or multi-tenant systems
Done prompt injection / jailbreak / LLM application security research on an agentic or AI-powered product
Previously shipped a coding agent, dev tool, or code-generation product end to end
Relevant security certifications (OSCP, OSWE) or notable bug bounty / CTF history. Nice to have, not required for this role
Enjoy building content and talking publicly about your work: blog posts, conference talks, or research writeups
We'd love for this role to help tell the story of how v0 approaches security, not just do the work quietly
Условия
Competitive compensation package, including equity
Inclusive Healthcare Package
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills
Flexible Time Off
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed
The San Francisco, CA base pay range for this role is $208,000.00 - $312,000
Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process
Vercel is committed to fostering and empowering an inclusive community within our organization
We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law
Паспорт вакансии
История публикации
Появилась в Вакандии29 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 29 дней назад
Среди похожихНет данных198 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего
Откуда что взялось
Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.
ГрейдSeniorвычитано из текста вакансии
Формат работыГибрид
ГеографияСан-Франциско, СШАвычитано из текста вакансии
Зарплата≈ 17 667 USD в месяцнаша оценка, в вакансии не названа
Почему на этом месте в выдаче
Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.
Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка
Проверка Вакандии
Источники и свежесть
Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
greenhouseОсновная публикация · 2026-07-16
V
Работодатель
Vercel
48 активных вакансий · вилка работодателя указана в 54%
Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайте — job-boards.greenhouse.io.
Признаки мошенничества
Просят предоплату, «залог» или деньги за обучение и оборудование.
Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
Быстро уводят в мессенджер и торопят с решением.
Обещают большой доход без опыта и без деталей задач.
Настоящий работодатель не просит денег и платёжных данных до трудоустройства.
Продолжить поиск
Похожие вакансии
Причина сходства указана на каждой карточке
G
Почему похожа: похожая специализация · тот же грейд