Primary record

Product Security Engineer

Vercel Indexed employerHybrid - San Francisco, New York City, London, Berlin · Berlin, Berlin, Germany · London, England, United Kingdom · New York, New York, United States · San Francisco, California, United States
Source-hosted applyChecked 1h agoInternship
Apply at Vercel

Vercel receives this application through Greenhouse. Babu Careers does not claim delivery.

Workplace

hybrid

Employment

Internship

Published

Aug 11, 2026

Closes

No date supplied

The role

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the Role:

Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does.

This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes.

More broadly, this is a mandate to rethink traditional security tooling for how Vercel actua

Requirements

Department: Security