> Markdown version of [/jobs/ext/2892730-senior-security-software-engineer-v0](https://www.wearedevelopers.com/jobs/ext/2892730-senior-security-software-engineer-v0). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Software Engineer, v0 - **Company:** Vercel - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £46,340.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software Debugging, Node.Js, Systems Development Life Cycle, Security Software, Software Engineering, TypeScript, Web Applications, ReactJS, Large Language Models, Software Security, Virtual Agents, Serverless Computing - **Published:** September 14, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5882600238 ## About the Role * Youre a software engineer first: 5+ years building and shipping production web applications, at a level where you operate independently (IC4/Senior). You can pick up a normal feature ticket and ship it end to end, this is not a pure audit/review role. * Strong full-stack fundamentals: Comfortable in TypeScript, React, and Node, and able to work in the same codebase, PR flow, and velocity as the rest of the v0 team. * Real security judgment: You understand authN/authZ design, sandboxing and isolation, injection vulnerability classes, and can reason about "an AI agent writing and running code" as a novel attack surface, even if your background so far has been primarily software engineering rather than a security title. * You influence through code, not just process: Youd rather fix the root cause in a PR than write a policy doc about it. You can be the security conscience of a fast-moving team without becoming its bottleneck. * Comfortable with ambiguity: v0s threat model is still being written. Youre excited to define it rather than inherit a mature playbook. * Willing to build with v0, not just secure it: Youre happy to actually go use v0 to build things and understand how our products work end to end, not just read the code from the outside. Bonus if you have * Already a v0 user or familiar with how it and Vercels broader product line work. * Hands-on experience with sandboxing, container isolation, or multi-tenant systems. * Done prompt injection / jailbreak / LLM application security research on an agentic or AI-powered product. * Previously shipped a coding agent, dev tool, or code-generation product end to end. * Relevant security certifications (OSCP, OSWE) or notable bug bounty / CTF history. Nice to have, not required for this role. * Enjoy building content and talking publicly about your work: blog posts, conference talks, or research writeups. Wed love for this role to help tell the story of how v0 approaches security, not just do the work quietly. ## Description v0 turns natural language into working, deployed applications. An agent writes code, executes it, and ships it on a users behalf. That makes v0 one of the most interesting and highest-stakes security surfaces at Vercel: sandboxed code execution, multi-tenant isolation, permission boundaries between what a user asked for and what the agent actually did, and resistance to prompt injection and tool misuse. Were looking for a Senior (IC4) software engineer with a strong security background to sit fully embedded inside the v0 team, not as a rotating auditor who reviews designs and files tickets, but as a peer engineer who owns security end to end for everything v0 ships. That means finding and fixing vulnerabilities yourself, building security features directly into the product, reviewing every new feature and launch before it goes out, and running the relationship with our HackerOne researcher community for anything v0-related. Youll spend real time being a great generalist engineer: building features, fixing bugs, shipping to production alongside the rest of the team. The difference is that you bring security judgment and hands-on ownership to everything the team builds, and youre the one who catches the sandbox escape, the auth gap, or the injection vector before it ships, rather than after. This role reports into the security organization but is deployed full-time with v0, and is evaluated as much on shipped product velocity as on security outcomes. As a senior (IC4) engineer, youre expected to operate independently, set the security bar for the team, and be trusted to make the final call on v0-specific tradeoffs. What you will do * Find and fix issues yourself: Proactively hunt for vulnerabilities across v0, from code youre reviewing to systems youre actively poking at, and ship the fix, not just the finding. * Build security features directly into the product: Design and implement the security-facing functionality itself (sandboxing/isolation controls, permission boundaries, abuse detection, safe defaults for generated apps) as a normal part of the v0 roadmap, not a side project. * Review all new v0 features and launches: Be the security reviewer of record for everything the team ships (new capabilities, generated-app patterns, integrations) before it goes out the door. * Own the HackerOne relationship for v0: Triage, validate, and drive fixes for reports from Vercels HackerOne researcher community that touch v0, and work directly with researchers on reproduction and remediation. * Own the v0 threat model: Understand and continuously refine how v0 generates, executes, and deploys code, including sandbox/runtime isolation, permission boundaries between agent actions and user intent, and defenses against prompt injection and tool-use abuse. * Harden code execution boundaries: Work directly on how agent-generated code is scoped, sandboxed, and constrained before it touches real infrastructure, including Vercels own sandbox and serverless runtimes. * Build guardrails that dont slow the team down: Create patterns, libraries, and checks that let v0 engineers ship new generated-app capabilities quickly without reintroducing known bug classes (auth, SSRF, injection) each time. * Partner with central Product Security: Share threat models, incident learnings, and SDLC tooling with the broader security team, while making the final call on v0-specific tradeoffs since you have the deepest context on the product. * Respond to v0-specific security reports and incidents: Be the first responder and technical owner when a security issue is reported against v0 specifically. * Think like an attacker, and like an agent: Reason about how a user, or an agent acting on that users behalf, could misuse v0 to attack itself, other tenants, or the platform underneath it. ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)