Talent.com
Senior Application Security Engineer Hybrid - San Francisco

Senior Application Security Engineer Hybrid - San Francisco

vercel.comSan Francisco, CA, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

About Vercel :

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, Chick-fil-A, and Under Armour build for the AI-native web.

Our mission is to enable the world ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story : You can just ship things.

About the Role :

We are looking for a Senior Application Security Engineer to join our security team (reporting to the Head of Security). In this role, you will drive critical application security initiatives across Vercel’s products and platform. Your core focus will be onthreat modeling, open-source software security, secure code review, SDLC tooling, andbug bounty program management. You will support both our internal product engineering teams and customer-facing security programs, ensuring that security is embedded throughout our development lifecycle and that our platform earns the trust of developers and end-users alike.

As a senior member of the team, you willlead cross-organizational security projects and champion a security-first culture within Vercel’s engineering organization. This is a high-impact role with broad scope – your work will not only secure Vercel’s core infrastructure and applications (built with Next.js, Node.js, and serverless architecture), but also influence the security of the open-source ecosystems we contribute to.

This is a hybrid role based at our San Francisco office with three days in the office per week.

What You Will Do :

  • Threat Modeling & Design Review : Partner with engineering and product teams to perform threat modeling for new and existing features. Identify potential risks early in the design phase and recommend security controls or design changes to mitigate threats. You will ensure security concerns are addressed from the inception of features through deployment.
  • Secure Code Review : Conduct secure code reviews and security assessments on applications and services built with Next.js, Node.js, and our serverless backend. You’ll uncover code-level vulnerabilities, provide actionable remediation guidance to developers, and establish best practices for secure coding across the engineering team.
  • Open Source Security Management : Oversee Vercel’s open-source security efforts. This includes monitoring and coordinating fixes for vulnerabilities in third-party open-source packages we use (as a consumer) and ensuring the security of the open-source projects we maintain and publish (as a contributor / publisher, e.g. Next.js). You will work with maintainers and the community on responsible disclosure and patching of security issues in open-source code.
  • SDLC Tooling & Automation : Evaluate, select, and integrate security tools into our Software Development Life Cycle. You will drive the implementation of automated security checks – for example, usingGitHub Advanced Security (GHAS)and other static analysis, dependency scanning, and secret detection tools – directly in our CI / CD pipelines and GitHub workflows. By embedding security tooling into developer workflows, you will help catch issues early and reduce manual effort.
  • Bug Bounty Program Management : Own and expand Vercel’s bug bounty program. You will triage and validate incoming vulnerability reports from the security researcher community, ensure critical issues are promptly addressed, and coordinate cross-team efforts to remediate and learn from reported vulnerabilities. You’ll also work on making our bug bounty a world-class, researcher-friendly program, including refining policies, scope, and engagement to encourage high-quality submissions.
  • Cross-Organizational Security Initiatives : Lead and contribute to security projects that span multiple teams and disciplines. For example, you might drive a company-wide upgrade to a more secure framework, implement a new authentication / authorization mechanism in collaboration with product teams, or roll out a security awareness program for engineers. You will act as asecurity championacross the org, aligning stakeholders from Engineering, DevOps, Product, and other groups to implement lasting security improvements.
  • Customer-Facing Security Support : Work closely with customer success and product marketing on security-related initiatives that impact our users. This may involve contributing to security documentation and whitepapers, assisting with customer security questionnaires or audits by providing application security expertise, and communicating our security features and best practices to build customer trust in the platform.

About You :

  • Experienced Security Engineer : You have 5+ years of experience in an Application Security or Product Security role (or related field), with a track record of securing web applications and services. You’re well-versed in the fundamentals of application security and have hands-on experience finding and fixing vulnerabilities.
  • Web Tech Stack Proficiency : Strong familiarity with JavaScript / TypeScript and Node.js runtime security. Experience with modern web frameworks (ideally Next.js or React and Node-based frameworks) and understanding of their security considerations. You can read and review code in these technologies to spot security flaws.
  • Threat Modeling & SDLC Expertise : Demonstrated ability to perform threat modeling and architectural risk analysis for complex applications. You understand how to integrate security into a fast-paced SDLC without slowing it down. Experience implementing or working with secure development lifecycle practices (secure design, code review, pentesting, etc.) is required.
  • Security Tools & Automation : Hands-on experience with application security tooling such as static application security testing (SAST), dynamic testing (DAST), dependency vulnerability scanners, and CI / CD pipeline security integration. Familiarity withGitHub Advanced Securityor similar tools for code scanning and secret detection is a strong plus.
  • Open Source and Supply Chain Security : Knowledge of open-source security best practices. You have experience dealing with open-source dependencies and package management security (e.g., handling vulnerability advisories, using tools like Dependabot or Snyk). Bonus if you have contributed to or maintained open-source projects, especially security-related ones.
  • Bug Bounty & Vulnerability Management : Exposure to running or participating in a bug bounty program or vulnerability disclosure process. You know how to assess externally reported issues, reproduce and validate vulnerabilities, and coordinate fixes. You stay up-to-date on the latest vulnerabilities (OWASP Top 10, emerging threats) and methods to mitigate them.
  • Cloud & Serverless Security Understanding : Solid understanding of cloud architecture and serverless environments from a security perspective. You are familiar with securing applications on cloud platforms (e.g., securing serverless functions, protecting APIs, managing secrets and keys). Experience with related cloud security concepts or tools is a plus.
  • Technical Leadership : Proven ability to drive security initiatives and influence engineering teams to adopt best practices. You can work cross-functionally to achieve security goals – for example, rolling out a new security tool or standard across many engineers. (While we emphasize technical skills, this senior role requires you to effectively communicate and lead within the organization to get things done.)
  • Bonus If You :

  • Have prior software development experience beyond security (e.g. as a frontend or backend engineer). Being able to empathize with developers and write or contribute code will help you integrate security seamlessly into development.
  • Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.
  • Experience with securitypolicy-as-codeor infrastructure as code security (for instance, using tools like Open Policy Agent, Terraform security checks, etc.). This shows you can bring security into the automation and infrastructure realm.
  • Have built or implemented security features in a product (such as authentication systems, encryption, secure CI / CD pipelines) or contributed to security community projects / tools.
  • Are an active participant in the security community (e.g., contributing to open source security projects, writing blog posts or research, attending or speaking at security conferences). A passion for continuous learning and sharing knowledge is always a plus on our team.
  • Benefits :

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
  • The San Francisco, CA base pay range for this role is $216,000-$324,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location, and the total package includes benefits and equity-based compensation. Your recruiter can share more details during the hiring process.

    Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

    #LI-LC1

    #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Application Security Engineer • San Francisco, CA, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Senior Security Controls Assessor

    Senior Security Controls Assessor

    VirtualVocationsFremont, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Controls Assessor to support a high-visibility federal program.Key Responsibilities Perform security and privacy control assessments for various systems...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Analyst

    Senior Security Analyst

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Analyst to monitor and respond to cybersecurity threats.Key Responsibilities Monitor and triage security alerts from various sources and lead incident r...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    FIPS Certified Security Engineer

    FIPS Certified Security Engineer

    VirtualVocationsFremont, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, FIPS / CC (Mobile Devices).Key Responsibilities Lead the end-to-end validation process for IT products, including security assessments and documentatio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Information Security Engineer

    Senior Information Security Engineer

    VirtualVocationsFremont, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Information Security Engineer who will contribute to the architecture, implementation, and ongoing support of a comprehensive, enterprise-grade security program.Ke...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Engineer to join their Information Security and Technology team.Key Responsibilities Drive decision-making for platform and application security a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Application Security Analyst

    Application Security Analyst

    VirtualVocationsConcord, California, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Security Analyst to protect its digital ecosystem.Key Responsibilities Analyze and refine security findings from various security tools Reduce false posit...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    VirtualVocationsFremont, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a FIPS 140 Security Engineer to support various FIPS 140 validation projects.Key Responsibilities Conduct general security analysis and design work for product architectu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cloud Security Engineer.Key Responsibilities Implement and automate security controls using AWS native tools and third-party solutions Monitor AWS environments ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    PAM Security Engineer

    PAM Security Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM / PAM Security Engineer to implement cybersecurity strategies for protecting digital identities within a federal agency's IT environment.Key Responsibilities Imple...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Engineer - Application Security

    Security Engineer - Application Security

    VirtualVocationsSan Francisco, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer - Application & AI Security (REMOTE).Key Responsibilities Build and deploy security controls across web applications, data pipelines, and AI systems; ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Security Software Engineer

    Senior Security Software Engineer

    VirtualVocationsSan Jose, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Software Engineer.Key Responsibilities Develop and maintain embedded software with a focus on security Implement and manage security protocols and auth...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Assurance Analyst

    Senior Security Assurance Analyst

    VirtualVocationsFremont, California, United States
    serp_jobs.job_card.full_time
    Security Assurance Analyst to lead the design, implementation, and optimization of enterprise information security controls and compliance programs. Key Responsibilities Lead and maintain SOC 2 an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    Cloud Software Group, Inc.San Ramon, CA, United States
    serp_jobs.job_card.full_time
    Analyze and investigate activity on company devices and infrastructure (Public Cloud & on-premise) that could represent a security threat. Work cross-functionally with the Security teams to develop ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Web Application Security Lead

    Web Application Security Lead

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Web Application Security Subject-Matter Expert (SME) / Technical Lead.Key Responsibilities : Lead the design, implementation, and management of the web application secur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Infrastructure Support Senior Security Engineer.Key Responsibilities : Design, install, maintain, and support enterprise IT systems across hybrid environments ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Engineer - Sensor Security

    Senior Engineer - Sensor Security

    VirtualVocationsOakland, California, United States
    serp_jobs.job_card.full_time
    Engineer - Sensor Security Platform (Remote).Key Responsibilities Understand, modify, and assume ownership of complex sensor detections and response capabilities Gain expertise in the core logic...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    WaymoMountain View, CA, United States
    serp_jobs.job_card.full_time
    Waymo is an autonomous driving technology company with the mission to be the world's most trusted driver.Since its start as the Google Self-Driving Car Project in 2009, Waymo has focused on buildin...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Sr. Information Security Engineer

    Sr. Information Security Engineer

    SupermicroSan Jose, CA, United States
    serp_jobs.job_card.full_time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Principal Security Engineer

    Principal Security Engineer

    VirtualVocationsSan Jose, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Principal Security Engineer (IC4).Key Responsibilities Contribute to the design, implementation, integration, and hands-on analyses to improve software behavior underst...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer to join their cybersecurity team.Key Responsibilities Administer and maintain identity providers and manage endpoint protection platforms Monitor and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30