高级安全软件工程师,v0
查看雇主原标题
Senior Security Software Engineer, v0Vercel · Hybrid - San Francisco, New York City, London, Berlin · $208k – $312k
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 65/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 已披露薪资
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 已披露薪资+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于 Vercel:
Vercel 是一家 agentic 基础设施公司。我们让人们和 agent 自由地交付下一个创新。
十多年来,Vercel 一直在塑造 Web 的构建方式。作为 Next.js、v0 和 AI SDK 背后的团队,我们打造的产品帮助构建者以速度、安全性和卓越的开发者体验,将想法变为生产环境。
如今,软件正进入一个新时代,下一代产品将不仅仅由人使用。它们将由 agent 构建、扩展和运营。
我们正在为那个未来构建平台,受到 OpenAI、PayPal、Ramp、Supreme 等公司以及全球数百万开发者的信赖。无论你是在构建我们的产品、支持我们的客户、壮大我们的社区,还是塑造我们的故事,你都将帮助定义接下来会发生什么。
岗位职责
v0 将自然语言转化为可运行、已部署的应用程序。一个 agent 代表用户编写代码、执行代码并发布代码。这使得 v0 成为 Vercel 最有趣、风险最高的安全面之一:沙箱化代码执行、多租户隔离、用户请求与 agent 实际行为之间的权限边界,以及对提示注入和工具滥用的抵御能力。
我们正在寻找一位具有深厚安全背景的资深(IC4)软件工程师,完全嵌入 v0 团队内部,不是那种轮岗式审查设计并提交工单的审计员,而是一位同行工程师,端到端负责 v0 发布的一切安全事务。这意味着你要自己发现并修复漏洞,将安全功能直接构建到产品中,在每一个新功能和发布上线前进行审查,并负责与我们的 HackerOne 研究员社区就所有与 v0 相关的事务保持关系。你将投入大量时间成为一名出色的通才工程师:构建功能、修复 bug、与团队其他成员一起发布到生产环境。不同之处在于,你为团队构建的一切带来安全判断和亲力亲为的责任感,并且你是在沙箱逃逸、认证缺口或注入向量发布之前就抓住它们的人,而不是之后。
该职位向安全组织汇报,但全职派驻在 v0 团队,评估标准既包括已交付产品的速度,也包括安全成果。作为资深(IC4)工程师,你需要独立运作,为团队设定安全标准,并被信任对 v0 特定的权衡做出最终决定。
• 自己发现并修复问题:主动在 v0 中寻找漏洞,从你正在审查的代码到你正在主动探测的系统,并交付修复方案,而不仅仅是发现。
• 将安全功能直接构建到产品中:作为 v0 路线图的正常组成部分,而非副项目,设计和实现面向安全的功能本身(沙箱/隔离控制、权限边界、滥用检测、生成应用的安全默认值)。
• 审查所有新的 v0 功能和发布:在团队发布的一切(新能力、生成应用模式、集成)上线之前,成为其正式的安全审查人。
• 负责 v0 的 HackerOne 关系:对 Vercel 的 HackerOne 研究员社区提交的涉及 v0 的报告进行分诊、验证并推动修复,并与研究员直接合作进行复现和补救。
• 负责 v0 威胁模型:理解并持续完善 v0 如何生成、执行和部署代码,包括沙箱/运行时隔离、agent 行为与用户意图之间的权限边界,以及对提示注入和工具使用滥用的防御。
• 加固代码执行边界:直接参与 agent 生成的代码在接触真实基础设施(包括 Vercel 自己的沙箱和无服务器运行时)之前如何被限定范围、沙箱化和约束。
• 构建不会拖慢团队的护栏:创建模式、库和检查,让 v0 工程师能够快速发布新的生成应用能力,而不会每次都重新引入已知的 bug 类别(认证、SSRF、注入)。
• 与中央产品安全团队合作:与更广泛的安全团队分享威胁模型、事件经验和 SDLC 工具,同时对 v0 特定的权衡做出最终决定,因为你对产品拥有最深入的背景。
• 响应 v0 特定的安全报告和事件:当针对 v0 的安全问题被报告时,成为第一响应者和技术负责人。
• 像攻击者一样思考,也像 agent 一样思考:推理用户或代表该用户行动的 agent 如何可能滥用 v0 来攻击自身、其他租户或其底层平台。
任职要求
• 你首先是一名软件工程师:5 年以上构建和交付生产 Web 应用的经验,达到能够独立运作的水平(IC4/资深)。你能够接手一个普通的功能工单并端到端交付,这不是一个纯粹的审计/审查职位。
• 扎实的全栈基础:熟悉 TypeScript、React 和 Node,能够与 v0 团队其他成员在同一代码库、PR 流程和速度下工作。
• 真正的安全判断力:你理解认证/授权设计、沙箱化和隔离、注入漏洞类别,并能够将“AI agent 编写和运行代码”作为一个新型攻击面进行推理,即使你迄今为止的背景主要是软件工程而非安全头衔。
• 你通过代码而非仅通过流程施加影响:你宁愿在 PR 中修复根本原因,也不愿写一份关于它的政策文档。你能够成为一个快速发展的团队的安全良知,而不会成为其瓶颈。
• 适应模糊性:v0 的威胁模型仍在编写中。你兴奋于定义它,而不是继承一套成熟的剧本。
• 愿意用 v0 构建,而不仅仅是保护它:你乐于真正使用 v0 来构建东西,并端到端理解我们的产品如何运作,而不仅仅是从外部阅读代码。
如果你具备以下条件则更佳
• 已经是 v0 用户,或熟悉它以及 Vercel 更广泛产品线的工作方式。
• 具有沙箱化、容器隔离或多租户系统的实践经验。
• 在 agentic 或 AI 驱动的产品上做过提示注入/越狱/LLM 应用安全研究。
• 曾端到端交付过编码 agent、开发工具或代码生成产品。
• 相关的安全认证(OSCP、OSWE)或著名的漏洞赏金/CTF 经历。加分项,非该职位必需。
• 喜欢构建内容并公开谈论你的工作:博客文章、会议演讲或研究文章。我们希望这个职位有助于讲述 v0 如何对待安全的故事,而不仅仅是默默做工作。
福利待遇
• 有竞争力的薪酬方案,包括股权。
• 包容性医疗保健套餐。
• 学习与成长——我们提供导师指导,并送你参加有助于建立人脉和技能的活动。
• 灵活休假。
• 我们将为你提供履行职责所需的装备,以及用于按需布置你空间的 WFH 预算。
该职位在加州旧金山的 base pay 范围为 $208,000.00 - $312,000.00。实际薪资将基于与工作相关的技能、经验和地点。旧金山以外的薪酬可能会根据员工所在地进行调整。总薪酬方案可能包括福利、基于股权的薪酬,以及根据职位不同而定的公司奖金或浮动薪酬计划的资格。你的招聘人员可以在招聘过程中分享更多细节。
Vercel 致力于在我们的组织内培养和赋能一个包容的社区。我们不会基于种族、宗教、肤色、性别表达或身份、性取向、国籍、公民身份、年龄、婚姻状况、退伍军人状况、残疾状况或任何其他受法律保护的特征进行歧视。Vercel 鼓励所有人申请我们的空缺职位,即使他们不一定满足职位描述中的每一项要求。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Vercel:
Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.
岗位职责
v0 turns natural language into working, deployed applications. An agent writes code, executes it, and ships it on a user's behalf. That makes v0 one of the most interesting and highest-stakes security surfaces at Vercel: sandboxed code execution, multi-tenant isolation, permission boundaries between what a user asked for and what the agent actually did, and resistance to prompt injection and tool misuse.
We're looking for a Senior (IC4) software engineer with a strong security background to sit fully embedded inside the v0 team, not as a rotating auditor who reviews designs and files tickets, but as a peer engineer who owns security end to end for everything v0 ships. That means finding and fixing vulnerabilities yourself, building security features directly into the product, reviewing every new feature and launch before it goes out, and running the relationship with our HackerOne researcher community for anything v0-related. You'll spend real time being a great generalist engineer: building features, fixing bugs, shipping to production alongside the rest of the team. The difference is that you bring security judgment and hands-on ownership to everything the team builds, and you're the one who catches the sandbox escape, the auth gap, or the injection vector before it ships, rather than after.
This role reports into the security organization but is deployed full-time with v0, and is evaluated as much on shipped product velocity as on security outcomes. As a senior (IC4) engineer, you're expected to operate independently, set the security bar for the team, and be trusted to make the final call on v0-specific tradeoffs.
• Find and fix issues yourself: Proactively hunt for vulnerabilities across v0, from code you're reviewing to systems you're actively poking at, and ship the fix, not just the finding.
• Build security features directly into the product: Design and implement the security-facing functionality itself (sandboxing/isolation controls, permission boundaries, abuse detection, safe defaults for generated apps) as a normal part of the v0 roadmap, not a side project.
• Review all new v0 features and launches: Be the security reviewer of record for everything the team ships (new capabilities, generated-app patterns, integrations) before it goes out the door.
• Own the HackerOne relationship for v0: Triage, validate, and drive fixes for reports from Vercel's HackerOne researcher community that touch v0, and work directly with researchers on reproduction and remediation.
• Own the v0 threat model: Understand and continuously refine how v0 generates, executes, and deploys code, including sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool-use abuse.
• Harden code execution boundaries: Work directly on how agent-generated code is scoped, sandboxed, and constrained before it touches real infrastructure, including Vercel's own sandbox and serverless runtimes.
• Build guardrails that don't slow the team down: Create patterns, libraries, and checks that let v0 engineers ship new generated-app capabilities quickly without reintroducing known bug classes (auth, SSRF, injection) each time.
• Partner with central Product Security: Share threat models, incident learnings, and SDLC tooling with the broader security team, while making the final call on v0-specific tradeoffs since you have the deepest context on the product.
• Respond to v0-specific security reports and incidents: Be the first responder and technical owner when a security issue is reported against v0 specifically.
• Think like an attacker, and like an agent: Reason about how a user, or an agent acting on that user's behalf, could misuse v0 to attack itself, other tenants, or the platform underneath it.
任职要求
• You're a software engineer first: 5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior). You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role.
• Strong full-stack fundamentals: Comfortable in TypeScript, React, and Node, and able to work in the same codebase, PR flow, and velocity as the rest of the v0 team.
• Real security judgment: You understand authN/authZ design, sandboxing and isolation, injection vulnerability classes, and can reason about "an AI agent writing and running code" as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title.
• You influence through code, not just process: You'd rather fix the root cause in a PR than write a policy doc about it. You can be the security conscience of a fast-moving team without becoming its bottleneck.
• Comfortable with ambiguity: v0's threat model is still being written. You're excited to define it rather than inherit a mature playbook.
• Willing to build with v0, not just secure it: You're happy to actually go use v0 to build things and understand how our products work end to end, not just read the code from the outside.
Bonus if you have
• Already a v0 user or familiar with how it and Vercel's broader product line work.
• Hands-on experience with sandboxing, container isolation, or multi-tenant systems.
• Done prompt injection / jailbreak / LLM application security research on an agentic or AI-powered product.
• Previously shipped a coding agent, dev tool, or code-generation product end to end.
• Relevant security certifications (OSCP, OSWE) or notable bug bounty / CTF history. Nice to have, not required for this role.
• Enjoy building content and talking publicly about your work: blog posts, conference talks, or research writeups. We'd love for this role to help tell the story of how v0 approaches security, not just do the work quietly.
福利待遇
• Competitive compensation package, including equity.
• Inclusive Healthcare Package.
• Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
• Flexible Time Off.
• We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.