Vercel07/17/2026
Инженер по безопасности ПО, Open Source Frameworks
Salary not specified
Hybrid - San Francisco
Responsibilities
- 01Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to identify systemic design patterns that produce whole families of vulnerabilities.
- 02Drive root‑cause framework fixes by pushing design changes upstream that eliminate entire vulnerability categories across all applications built on the framework.
- 03Own vulnerability disclosure and CVE processes: triage incoming security reports from the community and researchers for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro and other OSS projects; coordinate embargoed fixes, write and publish advisories, manage the CVE/CNA process end‑to‑end.
- 04Run Vercel’s open source bug bounty program for these projects: triage and validate incoming reports, reproduce findings, assess severity, and coordinate fixes with maintainers and researchers.
- 05Partner with framework maintainers and core teams during RFCs and design reviews to ensure security is considered from the first draft of new features.
- 06Build preventive tooling such as linters, codemods, and CI checks that catch regressions of previously‑fixed vulnerability classes before they land.
- 07Own supply chain security for the projects: harden how dependencies, releases, and published packages are built, signed, and distributed; develop review and provenance practices for AI‑assisted contributions.
- 08Engage directly with maintainers, contributors, and external researchers as peers, bringing pragmatic security recommendations to project discussions and representing Vercel in coordinated disclosure norms and working groups.
Requirements
- 01Hands‑on experience building real applications with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects), or having found and reported security issues in them.
- 02Deep appreciation and respect for open source work and its community maintainers, contributors, and users.
- 034+ years of experience in security engineering, preferably with hands‑on open source contribution experience.
- 04Track record of sending pull requests to projects like these, not just filing issues.
- 05Motivation rooted in finding root causes that eliminate whole classes of vulnerabilities rather than counting remediation tickets.
- 06Strong JavaScript/TypeScript fundamentals and genuine familiarity with modern meta‑framework internals (routing, SSR/RSC, middleware, bundling/build systems).
- 07Pragmatic mindset: able to weigh real‑world risk against maintainer and community bandwidth to ship security improvements that actually land.
- 08Experience with structured security assessment methodologies and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories.