InterviewHack.ai
Start free
Jobs / Vercel

Product Security Engineer

Vercel·Hybrid - San Francisco, New York City, London, Berlinmid

In short

  • →Construir sistemas automatizados para triage de vulnerabilidades de bug bounty a gran escala.
  • →Usar IA y agentes para analizar hallazgos complejos (lógica de negocio, autenticación) más allá de patrones simples.
  • →Ir más allá del triage: conectar hallazgos a causas raíz y proponer soluciones automáticamente.

No se requiere inglés explícitamente, pero el puesto es en inglés.

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

What they ask for

  • ✓Experiencia en construcción de herramientas de seguridad a gran escala.
  • ✓Capacidad para diseñar sistemas que usen IA/agentes para análisis de vulnerabilidades.
  • ✓Conocimiento en validación automatizada de hallazgos de seguridad externos.
  • ✓Habilidades sólidas de ingeniería de software con enfoque en escalabilidad.
  • ✓Interés en automatizar la remediación de vulnerabilidades.
  • ✓Capacidad para trabajar con LLMs o sistemas agenticos en contextos de seguridad.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

LLMagentsautomationsecurity toolingbug bounty triagereproducibilityseverity assessmentroot cause analysisremediation automationNext.js

Who should you write to at Vercel?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next. About the Role: Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn t scale past a certain volume, and Vercel is well past it. Adding more triagers doesn t close that gap. Building the systems that triage at that scale does. This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes. More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel s own surface. Because of this, we re optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we re looking for. If you re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you re located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team. What You Will Do: • Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match. • Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures. • Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in. • Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place. <

More jobs like this

Remote Security Engineer jobs

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Legal Counsel - Commercial

Vercel · Hybrid - San Francisco

→

Software Engineer, Agentic Infrastructure

Vercel · Hybrid - San Francisco, New York City

→

Software Engineer, Platform

Vercel · Hybrid - San Francisco, New York City

→

Member of the Technical Staff - Data Platform

Vercel · Remote - United States

→