All remote jobs
Open role
Remote opportunity atVercel

Security Engineer, Cloud

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
32Listing views
3Application actions
9 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

Vercel is seeking a senior Cloud Security Engineer to build and improve controls protecting its cloud-native platform. The role centers on infrastructure hardening, infrastructure-as-code, policy enforcement, service isolation, and secure CI/CD design. It partners closely with platform and infrastructure teams on threat modeling, risk mitigation, monitoring, detection, and incident response. The position requires 8+ years of infrastructure or platform security experience and deep AWS/GCP, IAM, Kubernetes, Terraform, and CDK knowledge. It is hybrid or fully remote for candidates within the United States.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThis is a senior, hands-on platform security role responsible for designing scalable controls in a high-growth cloud environment. It requires broad technical depth, sound security judgment, and the ability to influence engineering architecture and operational practices.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$260,000
US market range$190k–$290k
AI insightThe disclosed San Francisco base-pay range is USD 208,000 to USD 312,000 yearly, with a midpoint of USD 260,000. This is a senior cloud security engineering position; the estimated US market base-salary range is USD 190,000 to USD 290,000 yearly, varying by location, cloud-security depth, and scope of platform ownership. Equity and benefits are mentioned but are not included in the salary figures.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you approach securing a cloud-native platform that is growing quickly?

I would begin by identifying high-value assets, trust boundaries, and current control gaps through architecture reviews and threat modeling. I would prioritize scalable guardrails such as least-privilege IAM, policy-as-code, hardened deployment templates, centralized logging, and automated detection so security improves without creating unnecessary engineering friction.

Describe how you have used infrastructure as code to improve security.

I have used infrastructure-as-code workflows to make approved configurations repeatable and reviewable. This includes embedding secure defaults in Terraform modules, running policy checks in pull requests, preventing risky changes from reaching production, and continuously identifying drift from approved configurations.

What are key security considerations for Kubernetes environments?

Key areas include workload identity, RBAC least privilege, network segmentation, image provenance and scanning, admission controls, secrets management, runtime detection, and audit logging. I would also establish secure baseline configurations and make the compliant path the easiest path for application teams.

How do you balance strong security controls with developer velocity?

I focus on controls that are automated, transparent, and integrated into existing engineering workflows. I use risk-based prioritization, provide paved-road tooling and clear remediation guidance, and partner early with teams so controls solve real risks without adding avoidable manual approvals.

How would you improve platform-level detection and incident response?

I would map critical telemetry sources to likely threat scenarios, ensure logs are centralized and actionable, and create detections with clear ownership and response playbooks. I would then test the process through tabletop exercises and post-incident reviews, using lessons learned to improve both preventative controls and detection coverage.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role:

We’re looking for a Security Engineer to join our Cloud Security Engineering team. In this role, you’ll help strengthen the security of our platform by building and improving the controls that protect our infrastructure. You’ll play a key role in making security a core part of how we build, deploy, and scale our systems, while helping the company grow securely and confidently.

You’ll report to the Security Operations Manager, and this is a hybrid or fully remote within the United States. If you’re based within commuting distance of our SF or NY offices, the role includes in-office anchor days on Monday, Tuesday, and Friday.

What you will do:

  • Design and implement scalable security controls across our cloud-native platform.
  • Harden infrastructure components using infrastructure-as-code, policy enforcement, and service isolation.
  • Build secure by default infrastructure and code CI/CD pipelines.
  • Collaborate with platform and infrastructure teams to integrate security best practices into architecture and workflows.
  • Stay ahead of cloud security trends and adopt cutting-edge technologies to enhance platform resilience.
  • Conduct threat modeling, risk analysis, and mitigation planning for critical systems.
  • Drive improvements in monitoring, detection, and incident response at the platform level.
  • Build, deploy and maintain relevant tooling.

About you:

  • 8+ years of experience in infrastructure or platform security roles.
  • Deep understanding of secure cloud infrastructure (AWS/GCP), identity and access management, and system hardening.
  • Proficient with tools like Terraform, CDK, Kubernetes, and CI/CD security.
  • Skilled at balancing engineering realities with principled security practices.
  • Proven track record of shipping secure, resilient systems at scale.

Bonus if you:

  • Have built or scaled security automation pipelines.
  • Contributed to open-source security projects or tools.
  • Hold certifications such as GCP Security Engineer, AWS certifications, CISSP, or OSCP.
  • Hold a bachelors or masters degree in Cybersecurity or similar disciplines.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow – we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000.00 – $312,000.00. This salary range is an estimate. Actual salary will be based on job related skills, experience and location. Pay ranges outside San Francisco may be adjusted based on employee location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu