安全软件工程师,开源框架
查看雇主原标题
Security Software Engineer, Open Source FrameworksVercel · Hybrid - San Francisco, New York City, London, Berlin · $208k – $312k
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 65/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 已披露薪资
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 已披露薪资+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于 Vercel:
Vercel 是一家 agentic 基础设施公司。我们让人们和 agent 自由地交付下一个创新。
十多年来,Vercel 一直在塑造 Web 的构建方式。作为 Next.js、v0 和 AI SDK 背后的团队,我们打造的产品帮助构建者以速度、安全性和卓越的开发者体验,将想法变为生产环境。
如今,软件正进入一个新时代,下一代产品将不仅仅由人使用。它们将由 agent 构建、扩展和运营。
我们正在为那个未来构建平台,受到 OpenAI、PayPal、Ramp、Supreme 等公司以及全球数百万开发者的信赖。无论你是在构建我们的产品、支持我们的客户、壮大我们的社区,还是塑造我们的故事,你都将帮助定义接下来会发生什么。
岗位职责
Vercel 构建并维护着一系列广泛的开源项目,这些项目支撑着现代 Web,运行在数百万个应用中。你的主要关注点将是 Turborepo、Nuxt、Svelte/SvelteKit、SWR、Workflow 和 Nitro。在框架层面进行一次结构性修复,就能同时保护所有这些应用,这使其成为公司内影响力最高的安全岗位之一。
我们正在寻找一位安全工程师,他热衷于发现一整类漏洞并一举消除它们,而不是满足于一次提交一个 bug。你将深入评估框架内部(路由、中间件、缓存、server actions、构建流水线)的安全性,找出产生整类 bug 的系统性模式,并推动框架层面的修复和设计变更,永久消除它们。你还将负责这些项目如何处理外部报告的漏洞、协调披露和 CVE,直接与维护者和开源安全社区合作。这包括亲手负责 Vercel 针对这些项目的开源漏洞赏金计划:对收到的报告进行分诊、验证和复现发现,并与合适的维护者一起推动修复。
• 寻找漏洞类别,而非单个 bug:对框架内部(路由、中间件、缓存、数据获取、server actions/RSC 边界、构建工具)进行深入的安全评估,找出产生整类问题的系统性设计模式。
• 推动根因层面的框架修复:向上游推动设计变更,消除基于该框架构建的每个应用中的某一类漏洞,而不是在个别实例被报告时逐个修补。
• 负责漏洞披露和 CVE:对来自社区和研究人员针对 Turborepo、Nuxt、Svelte/SvelteKit、SWR、Workflow、Nitro 及其他维护中的 OSS 项目的安全报告进行分诊。协调禁运期修复,撰写并发布安全公告,并端到端管理 CVE/CNA 流程。
• 运营这些项目的 OSS 漏洞赏金计划:负责对 Vercel 针对 Turborepo、Nuxt、Svelte/SvelteKit、SWR、Workflow 和 Nitro 的开源漏洞赏金计划所收到报告的分诊和验证。复现发现、评估严重性,并与合适的维护者和研究人员协调修复。
• 让安全尽早进入设计:在 RFC 和设计评审期间与框架维护者和核心团队合作,使新功能从第一版草案起就考虑安全性,而不是在收到报告后才补上。
• 构建预防性工具:贡献 linter、codemod 和 CI 检查,在先前已修复的漏洞类别再次出现之前捕获其回归。
• 负责这些项目的供应链安全:加固 Turborepo、Nuxt、Svelte/SvelteKit、SWR、Workflow 和 Nitro 的依赖、发布和已发布包的构建、签名和分发方式。随着越来越多的贡献和依赖更新由 AI agent 生成或协助,建立审查和来源追溯实践,以确保这一增长的量是安全的。
• 与社区合作,而非绕开它:作为同行直接与维护者、贡献者和外部研究人员互动。以尊重这些项目实际构建方式的态度,将务实的安全建议带入项目讨论,并在问题跨越多个生态时,代表 Vercel 参与协调披露规范和 working group。
任职要求
• 你确实使用过或攻破过这些框架:你用 Turborepo、Nuxt、Svelte/SvelteKit、SWR、Workflow 或 Nitro(或密切可比的项目)构建过真实的东西,或者你曾发现并报告过其中的安全问题。这是硬性要求,而非加分项:我们需要的是理解这些项目实际做什么以及实际如何被使用的人,而不是空降而来的通才。
• 你对开源工作有深刻的理解和尊重:你明白这些是社区项目,维护者、贡献者和用户都非常关心它们,你以应有的严肃态度对待这一点。你来这里不是为了以流程本身为目的拖慢项目。
• 4 年以上安全工程经验,最好有真正亲手参与开源贡献的经验。你确实向类似这样的项目发送过 PR,而不仅仅是对它们提交 issue。
• 你被根因而非修复数量所激励:找到那个能消灭五十个潜在 bug 的设计缺陷,比一次关闭五十个工单更让你满足。
• 你能阅读框架内部,而不仅仅是应用代码:扎实的 JavaScript/TypeScript 基础,并真正熟悉现代元框架在底层如何工作(路由、SSR/RSC、中间件、打包/构建系统)。
• 务实,而非理论化:你能权衡现实世界风险与维护者和社区的精力,并达成真正能发布的安全改进,而不是永远不会被合并的理论上完美的修复。
• 漏洞研究能力:具有结构化安全评估方法论和协调/负责任披露流程的经验,包括处理禁运期和撰写清晰的安全公告。
• 清晰的沟通者:你能以书面和对话方式,向维护者、贡献者和非安全工程师清晰解释漏洞、权衡或设计建议。
• 能在公开环境中自如运作:你习惯于与外部研究人员、维护者和社区透明地合作,而不仅仅是在公司内部。
如果你具备以下条件则更佳
• 拥有 CVE 署名或已发表的安全研究,尤其是在 JavaScript 框架或 Node 生态中。
• 维护过或大量贡献过一个被广泛使用的开源项目。
• 具有供应链安全工具(Sigstore、SLSA/provenance、依赖和包扫描)的经验。
• 思考过越来越多的 AI agent 撰写的贡献如何改变开源维护的风险模型。
• 以前运营过或分诊过漏洞赏金/漏洞披露计划,最好是为开源项目。
福利待遇
• 有竞争力的薪酬方案,包括股权。
• 包容性的医疗保健方案。
• 学习与成长——我们提供导师指导,并送你参加有助于建立人脉和技能的活动。
• 灵活休假。
• 我们将提供你履行职责所需的装备,以及 WFH 预算,供你按需布置自己的空间。
该职位在加州旧金山的 base pay 范围为 $208,000.00 - $312,000.00。实际薪资将基于与工作相关的技能、经验和地点。旧金山以外的薪酬可能会根据员工所在地进行调整。总薪酬方案可能包括福利、基于股权的薪酬,以及根据职位不同而定的公司奖金或浮动薪酬计划的资格。你的招聘人员可以在招聘过程中分享更多细节。
Vercel 致力于在我们的组织内培养和赋能一个包容的社区。我们不会基于种族、宗教、肤色、性别表达或身份、性取向、国籍、公民身份、年龄、婚姻状况、退伍军人身份、残疾状况或任何其他受法律保护的特征进行歧视。Vercel 鼓励所有人申请我们的空缺职位,即使他们不一定满足职位描述中的每一项要求。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Vercel:
Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.
岗位职责
Vercel builds and maintains a broad portfolio of open source projects that power the modern web, running in millions of applications. Your primary focus will be Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro . A single structural fix at the framework level protects every one of those applications at once, which makes this one of the highest-leverage security roles at the company.
We're looking for a security engineer who loves finding a whole class of vulnerability and eliminating it in one move, not someone who's satisfied filing one bug at a time. You'll run deep security assessments of framework internals (routing, middleware, caching, server actions, the build pipeline), find the systemic patterns that produce entire families of bugs, and drive the framework-level fixes and design changes that remove them permanently. You'll also own how these projects handle externally reported vulnerabilities, coordinated disclosure, and CVEs, working directly with maintainers and the open source security community. This includes hands-on ownership of Vercel's open source bug bounty program for these projects: triaging incoming reports, validating and reproducing findings, and driving fixes with the right maintainers.
• Hunt for vulnerability classes, not individual bugs: Run deep security assessments of framework internals (routing, middleware, caching, data fetching, server actions/RSC boundaries, build tooling) to find the systemic design patterns that produce whole families of issues.
• Drive root-cause framework fixes: Push design changes upstream that eliminate a category of vulnerability across every application built on the framework, rather than patching individual instances as they're reported.
• Own vulnerability disclosure and CVEs: Triage security reports from the community and researchers across Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, Nitro, and other maintained OSS projects. Coordinate embargoed fixes, write and publish advisories, and manage the CVE/CNA process end to end.
• Run the OSS bug bounty program for these projects: Own triage and validation of incoming reports to Vercel's open source bug bounty program for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro. Reproduce findings, assess severity, and coordinate fixes with the right maintainers and researchers.
• Get security into design early: Partner with framework maintainers and core teams during RFCs and design review, so new features ship with security considered from the first draft, not bolted on after a report comes in.
• Build preventive tooling: Contribute linters, codemods, and CI checks that catch regressions of previously-fixed vulnerability classes before they land again.
• Own supply chain security for these projects: Harden how dependencies, releases, and published packages for Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, and Nitro are built, signed, and distributed. As more contributions and dependency updates are generated or assisted by AI agents, build the review and provenance practices that keep that increased volume safe.
• Work with the community, not around it: Engage directly with maintainers, contributors, and external researchers as peers. Bring pragmatic security recommendations to project discussions in a way that respects how these projects actually get built, and represent Vercel in coordinated disclosure norms and working groups when an issue spans multiple ecosystems.
任职要求
• You've actually used or broken these frameworks: You've built real things with Turborepo, Nuxt, Svelte/SvelteKit, SWR, Workflow, or Nitro (or closely comparable projects), or you've found and reported security issues in them. This is a hard requirement, not a nice-to-have: we need someone who understands what these projects actually do and how they're actually used, not a generalist parachuting in.
• You have a deep appreciation and respect for open source work: You understand that these are community projects with maintainers, contributors, and users who care deeply about them, and you treat that with the seriousness it deserves. You're not here to slow the project down with process for its own sake.
• 4+ years in security engineering, ideally with real hands-on open source contribution experience. You've actually sent PRs to projects like these, not just filed issues against them.
• You're energized by root cause, not remediation count: Finding the one design flaw that kills fifty potential bugs is more satisfying to you than closing fifty tickets one at a time.
• You can read framework internals, not just application code: Strong JavaScript/TypeScript fundamentals and genuine familiarity with how modern meta-frameworks work under the hood (routing, SSR/RSC, middleware, bundling/build systems).
• Pragmatic, not theoretical: You can weigh real-world risk against maintainer and community bandwidth, and land on security improvements that actually ship, rather than the theoretically ideal fix that never gets merged.
• Vulnerability research chops: Experience with structured security assessment methodology and coordinated/responsible disclosure processes, including handling embargoes and writing clear advisories.
• Clear communicator: You can explain a vulnerability, a tradeoff, or a design recommendation clearly to maintainers, contributors, and non-security engineers alike, in writing and in conversation.
• Comfortable operating in public: You're used to working transparently with external researchers, maintainers, and the community, not just inside a company's four walls.
Bonus if you have
• CVE credits or published security research, especially in JavaScript frameworks or the Node ecosystem.
• Maintained or heavily contributed to a widely used open source project.
• Experience with supply chain security tooling (Sigstore, SLSA/provenance, dependency and package scanning).
• Thought about how increasing AI-agent-authored contributions change the risk model for open source maintenance.
• Run or triaged for a bug bounty / vulnerability disclosure program before, ideally for open source projects.
福利待遇
• Competitive compensation package, including equity.
• Inclusive Healthcare Package.
• Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
• Flexible Time Off.
• We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.