Security Automation Engineer

  1. Careers /
  2. Security & IT
  • Security & IT
  • Hybrid (San Francisco)
  • Full Time

About Vercel:

Vercel’s Frontend Cloud provides the developer experience and infrastructure to build, scale, and secure a faster, more personalized web. Customers like Under Armour, eBay, The Washington Post, Johnson & Johnson, and Zapier use Vercel to build dynamic user experiences on the web.

At Vercel, our mission is to enable the world to ship the best products and that goes hand in hand with creating an environment where you can do the best work of your life.

About the Role:

We are looking for an Automation Engineer to join our Security team. This role will focus on building internal security tools, automating secure design reviews, and integrating security guidance directly into pull requests. Your work will empower both the security and development teams by reducing friction in the security review process and ensuring best practices are embedded seamlessly into the Software Development Lifecycle (SDLC).

This is a hybrid role based at our San Francisco office with two days in the office per week.

What You Will Do:

  • Develop and maintain security automation tooling to enhance visibility, enforce security best practices, and streamline processes.

  • Automate secure design reviews and integrate security checks into pull request workflows and CI/CD pipelines.

  • Build and manage security operations automation, including data pipelines, SOAR workflows, and log aggregation for improved threat detection.

  • Collaborate with development and security teams to ensure seamless adoption of security automation.

  • Continuously refine automation strategies to optimize security effectiveness and reduce manual overhead.

  • Support on-going vulnerability management efforts to ensure proper attack surface management.

About You:

  • Experience building automation tooling for security or developer efficiency.

  • Proficiency in at least one scripting language (Python, JavaScript, or Bash) and familiarity with a compiled language (Go, Rust, or Java).

  • Experience with GitHub automation and API integrations.

  • Strong understanding of CI/CD pipelines and how to integrate security into development workflows.

  • Knowledge of infrastructure-as-code security best practices and automation techniques.

  • Ability to collaborate effectively across security and engineering teams.

Bonus If You:

  • Have experience with security policy-as-code frameworks.

  • Have worked on integrating security controls into developer workflows at scale.

  • Have experience with modern cloud-native security tooling and practices.

Benefits:

  • Competitive compensation package, including equity.

  • Inclusive Healthcare Package.

  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.

  • Flexible Time Off.

  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

#LI-LC1

Apply Now.

Tell us why you’d be a good fit for the Security Automation Engineer role.

Resume should be a PDF under 3.5MB.

Are you currently based in any of these countries? Please note these are the only countries where we are accepting applications

Will you require Visa Sponsorship now, or in the future?

Do you live in one of the following states? Alabama, Alaska, Delaware, Kansas, Maine, Mississippi, Montana, Nebraska, New Mexico, North Dakota, South Dakota, West Virginia, or Wyoming.

This role requires a hybrid schedule with 2 days per week in our SF office. Are you willing to commit to this hybrid schedule?

By submitting my application, I acknowledge that I have read and understand Vercel’s Job Applicant Privacy Notice

Please double-check all the information provided above. Ensuring accuracy is crucial, as any errors or omissions may impact the review of your application.

U.S. Standard Demographic Questions.

At Vercel, we value belonging and believe in fostering an environment where a diversity of perspectives can thrive. As part of this commitment, we invite you to voluntarily provide demographic information. Your responses will be used (in aggregate only) to help us better understand the diversity of our applicants and identify areas of improvement in our recruitment and hiring process. Your responses, or decision not to respond, will be kept confidential and will only be used in aggregate form for diversity and inclusion efforts. This information will not be associated with your specific application and will not be disclosed to the hiring team or used in the hiring decision in any way.

Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, or sexual orientation. Asking the below questions help us comply with federal and state Equal Employment Opportunity/Affirmative Action record keeping, reporting, and other legal requirements.

How would you describe your gender identity? (mark all that apply)

How would you describe your racial/ethnic background? (mark all that apply)

How would you describe your sexual orientation? (mark all that apply)

Do you identify as transgender?

Do you have a disability or chronic condition (physical, visual, auditory, cognitive, mental, emotional, or other) that substantially limits one or more of your major life activities, including mobility, communication (seeing, hearing, speaking), and learning?

Are you a veteran or active member of the United States Armed Forces?

Optionally, include links to your social media profiles.