Security Researcher

  1. Careers /
  2. Security & IT
  • Security & IT
  • Remote (United States)
  • Full Time

About Vercel:

Vercel’s Frontend Cloud provides the developer experience and infrastructure to build, scale, and secure a faster, more personalized web. Customers like Under Armour, eBay, The Washington Post, Johnson & Johnson, and Zapier use Vercel to build dynamic user experiences on the web.

At Vercel, our mission is to enable the world to ship the best products and that goes hand in hand with creating an environment where you can do the best work of your life.

About the Role:

Vercel is seeking a Security Researcher to strengthen our security posture through vulnerability research, particularly focusing on Vercel-maintained open-source projects like Next.js. You'll spearhead efforts to discover, report, and mitigate new security threats, develop framework-specific WAF rule packs (for Next.js, Svelte, and others), and improve product security by providing tailored, actionable guidance to our customers.

In this role, you'll represent Vercel at industry conferences, share research findings to establish thought leadership, and work closely with engineering, marketing, and customer success teams. You'll create educational materials, publish insights, and align product improvements with customer needs. This work will help customers maximize their application security through Vercel's native features while strengthening our position as a leader in application security and proactive threat mitigation.

What You Will Do:

  • Customer-Centric WAF Rule Development

    • Design WAF rule packs tailored to specific frameworks, such as Next.js, prioritizing rules that address the most relevant and framework-specific vulnerabilities.

    • Continuously refine these rules using real-time threat data, research findings, and customer feedback to maintain strong protection against emerging attack patterns.

  • Enablement through Education and Documentation

    • Create clear documentation, guides, and best practices for Vercel's WAF to help customers understand and set up security rules that match their specific needs.

    • Create educational materials and host webinars or workshops that equip customers with practical knowledge on utilizing Vercel's WAF to its full potential.

  • Proactive Threat Intelligence for Customers

    • Share research-based threat intelligence with customers to alert them about potential risks and provide specific recommendations for rule updates and configurations.

    • Work with customer success teams to identify and address high-risk customer environments, ensuring WAF configurations match each customer's unique security needs.

  • Collaborate on Security Feature Enhancements

    • Work closely with Vercel’s product team to ensure that customer-facing security features align with industry standards and emerging threats, making Vercel’s WAF adaptable to various customer applications.

    • Share insights from vulnerability research and customer feedback to shape product roadmaps, focusing on features that improve WAF effectiveness and usability across different customer needs.

  • Develop Security Tooling and Self-Service Enablement

    • Build tools or dashboards that allow customers to self-assess and monitor the effectiveness of WAF configurations, offering insights into blocked threats, rule performance, and custom rule capabilities.

    • Explore opportunities for customer-driven customization of WAF rules, empowering customers to address unique vulnerabilities while maintaining a default layer of robust security.

  • Customer Advocacy and Success Collaboration

    • Partner with customer success and support teams to address WAF-related inquiries, share guidance, and resolve complex security configurations.

    • Collect and synthesize customer feedback to continuously improve the WAF experience and address emerging needs in Vercel’s customer base.

About You:

  • Vulnerability Research Expertise: Proven experience identifying, reporting, and mitigating security vulnerabilities in open-source projects.

  • WAF Knowledge: Hands-on experience with Web Application Firewalls, ideally with rule customization and framework-specific tuning.

  • Strong Communication Skills: Ability to convey complex security concepts to both technical and non-technical audiences, including conference presentations and blog writing.

  • Cross-Functional Collaboration: Experience working closely with engineering, marketing, and customer success teams to drive security initiatives.

  • Customer Enablement Focus: Skilled in creating educational materials and supporting documentation for customers to optimize WAF configurations.

  • Industry Awareness: Familiarity with current security trends and emerging threats, with a proactive approach to continuous learning and application.

Bonus If You:

  • Built a Web Application Firewall Security product directly as an engineer

  • Achieved an Offensive Security certification and or Advanced SANS certification.

Benefits:

  • Great compensation package and stock options.

  • Inclusive Healthcare Package.

  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.

  • Flexible Time Off - Flexible vacation policy with a recommended 4-weeks per year, and paid holidays.

  • Remote Friendly - Work with teammates from different time zones across the globe.

  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $216,000-$300,000.  This salary range is an estimate. Actual salary will be based on job related skills, experience and location. Pay ranges outside San Francisco may be  adjusted based on employee location.  The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

#LI-LC1

Perks:

  • Generous Gear Credit
  • Flexible Time Off
  • Stock Options
  • Remote Friendly

Apply Now.

Tell us why you’d be a good fit for the Security Researcher role.

Resume should be a PDF under 3.5MB.

Are you currently based in any of these countries:

Will you require Visa Sponsorship now, or in the future?

Do you live in one of the following states? Alabama, Alaska, Delaware, Kansas, Maine, Mississippi, Montana, Nebraska, New Mexico, North Dakota, South Dakota, West Virginia, or Wyoming.

Where did you hear about us?

By submitting my application, I acknowledge that I have read and understand Vercel’s Job Applicant Privacy Notice

Please double-check all the information provided above. Ensuring accuracy is crucial, as any errors or omissions may impact the review of your application.

U.S. Standard Demographic Questions.

At Vercel, we value belonging and believe in fostering an environment where a diversity of perspectives can thrive. As part of this commitment, we invite you to voluntarily provide demographic information. Your responses will be used (in aggregate only) to help us better understand the diversity of our applicants and identify areas of improvement in our recruitment and hiring process. Your responses, or decision not to respond, will be kept confidential and will only be used in aggregate form for diversity and inclusion efforts. This information will not be associated with your specific application and will not be disclosed to the hiring team or used in the hiring decision in any way.

Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, or sexual orientation. Asking the below questions help us comply with federal and state Equal Employment Opportunity/Affirmative Action record keeping, reporting, and other legal requirements.

How would you describe your gender identity? (mark all that apply)

How would you describe your racial/ethnic background? (mark all that apply)

How would you describe your sexual orientation? (mark all that apply)

Do you identify as transgender?

Do you have a disability or chronic condition (physical, visual, auditory, cognitive, mental, emotional, or other) that substantially limits one or more of your major life activities, including mobility, communication (seeing, hearing, speaking), and learning?

Are you a veteran or active member of the United States Armed Forces?

Optionally, include links to your social media profiles.