# Security Software Engineer, Open Source Frameworks at Vercel

- Company: Vercel
- What the company does: The autonomous stack for every app and agent. Backed by Accel, General Catalyst and Khosla.
- Company website: https://vercel.com/
- Type: Startups (AI role)
- Level: Mid level
- Location: Hybrid - San Francisco, New York City, London, Berlin
- Work setup: Hybrid
- Posted: 2026-07-16
- Apply by: 2026-10-08
- Apply: https://job-boards.greenhouse.io/vercel/jobs/6117204004
- Page: https://www.1752.vc/careers/jobs/vercel-security-software-engineer-open-source-frameworks/

## About the role

Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro . A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company.

## What they're looking for

- 4+ years in security engineering, ideally with real hands-on open source contribution experience. You've actually sent PRs to projects like these, not just filed issues against them
- You're energized by root cause, not remediation count: Finding the one design flaw that kills fifty potential bugs is more satisfying to you than closing fifty tickets one at a time
- Pragmatic, not theoretical: You can weigh real-world risk against maintainer and community bandwidth, and land on security improvements that actually ship, rather than the theoretically ideal fix that never gets merged
- Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories
- Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike, in writing and in conversation
- Comfortable operating in public: You're used to working transparently with external researchers, maintainers, and the community, not just inside a company's four walls

Tags: Security
