New RJRP now shows Market-Observed Roles alongside verified postings — scored by our Hiring Activity algorithm. How it works →
🔍
Market-Observed Role 🔍 Observed Likely Active (65-79)
This role was detected through Vercel's hiring system and hasn't been verified directly by the employer. Our algorithm scored it as Likely Active (65-79) based on freshness, specificity, and company patterns. What does this mean? →

Senior Product Security Engineer

Vercel
🔍 Observed
66
Hiring Activity Score
Likely Active (65-79)
  • Base score
  • Posted 21 days ago
  • has location, quality description (11397 chars)
  • 10 skills
  • High confidence (90%)
  • Direct ATS (greenhouse)
How the Hiring Activity Score works →
Remote - United States First seen 3 weeks, 1 day ago Last seen 9 hours, 14 minutes ago Greenhouse
Apply on Greenhouse Search Google for This Role

ATS links often expire — Google search finds the latest posting

Job Description

AI Summary
• Lead product security initiatives including threat modeling, secure code reviews, and SDLC tooling for Vercel's Next.js, Node.js, and serverless platforms • Manage open-source security for both consumed and published projects, coordinating vulnerability fixes and responsible disclosure across the ecosystem • Partner with engineering teams to embed security early in the design phase and establish secure coding best practices across the organization • Oversee bug bounty program management and support customer-facing security programs to build developer trust • Hybrid or remote role based on location (anchor days Mon/Tue/Fri in SF, NY, London, or Berlin offices for those nearby; fully remote otherwise)

Skills

node.js go terraform react typescript aws rust java git javascript
Job Information
  • Company:
    Vercel
  • Location:
    Remote - United States
  • Job Type:
    Internship
  • Work Location:
    Remote
  • Experience Level:
    Senior
  • Source:
    Greenhouse
  • Status:
    Active
Activity Score
66 /100
Likely Active (66)

Higher scores indicate more likely active hiring based on listing freshness, company activity, and other signals. Learn more →

More from Vercel
+
🔍

We now show two types of job listings

Same commitment to real jobs. More opportunities for you. Here's how it works.

✓ Verified Employer-Verified Posts

These jobs were posted directly to RJRP by the employer. The company has been verified through our multi-step process. This is our gold standard — the employer is real, the job is real, and you can apply with confidence.

✓ 100% employer verified
🔍 Observed Market-Observed Roles

These roles were detected through employer hiring systems like Workday. They haven't been verified by the employer directly, so we score each one using our Hiring Activity Score — an algorithm that analyzes freshness, specificity, company hiring patterns, and more to estimate whether the role is actively being filled.

📊 Only high-scoring listings are shown

Our promise hasn't changed. We will never show you a listing we can't stand behind. Market-observed roles must pass our scoring threshold before they appear on RJRP. Anything that looks like a ghost job, a talent pipeline, or a dead listing gets filtered out — you'll never see it.