InterviewHack.ai
Empezar gratis
Vacantes / Vercel

Security Software Engineer, Open Source Frameworks

Vercel·Hybrid - San Francisco, New York City, London, Berlinsenior

En corto

  • →Ingeniero de seguridad enfocado en encontrar vulnerabilidades sistémicas en frameworks open source como Turborepo, Nuxt y SvelteKit.
  • →A nivel diario, investiga patrones de diseño que generan familias enteras de bugs y lidera soluciones desde el origen en los frameworks.
  • →Lo más destacado: una corrección de diseño puede proteger millones de aplicaciones a la vez.

Fluent English required for collaboration with global open source community and maintainer

Postularme en la empresa ↗Compartir por WhatsApp

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Gratis, sin tarjeta.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

¿Qué piden?

  • ✓Experiencia comprobada en auditorías de seguridad de frameworks o herramientas de construcción de software.
  • ✓Capacidad para identificar patrones sistémicos de vulnerabilidades más allá de casos aislados.
  • ✓Conocimiento profundo de arquitecturas web modernas: routing, middleware, server actions, build pipelines.
  • ✓Experiencia práctica en triage, validación y coordinación de reportes de seguridad y CVEs.
  • ✓Habilidades para colaborar con equipos de mantenimiento de proyectos open source.
  • ✓Capacidad para influir en decisiones de diseño desde etapas tempranas (RFCs, revisión de diseño).

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

TurborepoNuxtSvelte/SvelteKitSWRWorkflowNitroNext.jsv0AI SDKGitHub

¿A quién escribirle en Vercel?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next. About the role Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro . A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company. We re looking for a security engineer who loves finding a whole class of vulnerability and eliminating it in one move, not someone who s satisfied filing one bug at a time. You ll run deep security assessments of framework internals (routing, middleware, caching, server actions, the build pipeline), find the systemic patterns that produce entire families of bugs, and drive the framework-level fixes and design changes that remove them permanently. You ll also own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. This includes hands-on ownership of Vercel s open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right maintainers. What you will do • Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues. • Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they re reported. • Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end. • Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel s open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers. • Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in. • Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before

¿Buscando algo parecido?

Dejá tu email y te avisamos cuando salgan vacantes que coincidan con tu perfil.

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesEmpresas contratandoRevisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Reporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaEs gratis

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

Legal Counsel - Commercial

Vercel · Hybrid - San Francisco

→

Software Engineer, Agentic Infrastructure

Vercel · Hybrid - San Francisco, New York City

→

Software Engineer, Platform

Vercel · Hybrid - San Francisco, New York City

→

Member of the Technical Staff - Data Platform

Vercel · Remote - United States

→