Senior Security Software Engineer, v0

VercelBerlin, CA
$208,000 - $312,000

About The Position

Vercel is seeking a Senior Security Software Engineer to embed within the v0 team. This role is not a traditional auditing position but a peer engineering role responsible for end-to-end security ownership of v0. The engineer will proactively identify and fix vulnerabilities, build security features directly into the product, review all new features and launches, and manage the HackerOne researcher community for v0. The role requires a strong generalist engineering skillset, including feature building and bug fixing, combined with deep security judgment and hands-on ownership. The position reports to the security organization but is fully deployed with v0, with performance evaluated on both product velocity and security outcomes. As a senior engineer (IC4), the individual is expected to operate independently, set security standards for the team, and make final decisions on v0-specific tradeoffs.

Requirements

  • 5+ years of experience building and shipping production web applications at a senior level (IC4 or equivalent), capable of independently shipping features end-to-end.
  • Strong full-stack fundamentals, with comfort in TypeScript, React, and Node.js, able to work within the v0 team's codebase, PR flow, and velocity.
  • Demonstrated security judgment, including understanding of authentication/authorization design, sandboxing and isolation, and injection vulnerability classes.
  • Ability to reason about the security implications of an AI agent writing and running code, even with a primary background in software engineering.
  • Preference for influencing through code and direct fixes rather than solely relying on policy documentation.
  • Ability to act as the security conscience of a fast-moving team without becoming a bottleneck.
  • Comfort with ambiguity and a willingness to define the threat model for a novel product.
  • Willingness to use v0 to build things and understand the product end-to-end, not just analyze code externally.

Nice To Haves

  • Existing user of v0 or familiarity with Vercel's product line.
  • Hands-on experience with sandboxing, container isolation, or multi-tenant systems.
  • Experience with prompt injection, jailbreaking, or LLM application security research on agentic or AI-powered products.
  • Previous experience shipping a coding agent, dev tool, or code-generation product end-to-end.
  • Relevant security certifications (e.g., OSCP, OSWE) or notable bug bounty/CTF history.
  • Experience building content such as blog posts, conference talks, or research writeups, and a willingness to publicly share work.

Responsibilities

  • Proactively hunt for vulnerabilities across v0, from code review to active system probing, and ship fixes.
  • Design and implement security-facing functionality, such as sandboxing/isolation controls, permission boundaries, abuse detection, and safe defaults for generated applications, as a core part of the v0 roadmap.
  • Serve as the security reviewer of record for all v0 team shipments, including new capabilities, generated-app patterns, and integrations, before they are launched.
  • Manage the HackerOne relationship for v0, including triaging, validating, and driving fixes for researcher reports, and collaborating with researchers on reproduction and remediation.
  • Own and continuously refine the v0 threat model, covering aspects like sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool-use abuse.
  • Work directly on hardening code execution boundaries, including scoping, sandboxing, and constraining agent-generated code before it interacts with infrastructure.
  • Create patterns, libraries, and checks that enable v0 engineers to rapidly ship new generated-app capabilities without reintroducing known bug classes.
  • Collaborate with the central Product Security team by sharing threat models, incident learnings, and SDLC tooling, while making final decisions on v0-specific tradeoffs.
  • Act as the first responder and technical owner for v0-specific security reports and incidents.
  • Reason about potential misuse of v0 by users or agents to attack the system, other tenants, or the underlying platform.

Benefits

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow opportunities, including mentorship and event attendance for networking and skill-building.
  • Flexible Time Off.
  • Provision of necessary gear and a WFH budget for home office setup.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service