安全软件工程师,身份与访问管理
Security Software Engineer, IAM
关于 Vercel:
Vercel 是一家代理型基础设施公司。我们让个人和代理能够快速交付未来的产品。
在过去十多年里,Vercel 改变了网页的构建方式。作为 Next.js、v0 和 AI SDK 的团队,我们创建了帮助开发者从想法到生产快速构建的产品。
现在,软件进入了一个新时代,下一代产品将不仅由人使用,还将由代理来构建、扩展和运行。
我们正在为这个未来打造平台,受到 OpenAI、PayPal、Ramp、Supreme 等公司的信任,以及全球数百万开发者的信赖。无论你是构建我们的产品、支持我们的客户、壮大我们的社区,还是塑造我们的故事,你都将定义未来的方向。
关于职位:
我们正在寻找一名安全软件工程师加入我们的安全团队,负责 Vercel 的身份与访问管理策略——涵盖企业及生产环境。这是一项高影响力、高度自主的职位:你将从零开始定义 IAM 架构,将 Okta 全面迁移到 Terraform,并成为整个组织在 IAM 最佳实践方面的专家。
你将向安全负责人汇报工作,并远程位于美国。如果你住在旧金山或纽约办公室附近,该职位包含每周一、二、五的线下办公日。
你将负责:
- 负责企业及生产环境的完整 IAM 策略——从路线图、标准到架构的全流程定义
- 将 Okta 及所有相关 IAM 配置迁移至 Terraform,推动基础设施即代码的采用,并提升工程团队在其中的使用能力
- 领导 Vercel-on-Vercel 和 Vercel 基础设施清理项目,确保我们的内部系统符合我们对外销售的标准
- 在云、SaaS 和生产基础设施上设计并实施最小权限访问控制
- 与平台和工程团队合作,在设计阶段早期嵌入 IAM 最佳实践
- 构建和管理 MDM/MAM 工具,以保障组织内端点和移动设备的访问安全
- 推动在供应、撤销和访问审查流程中的自动化
- 在安全、IT 和工程团队中担任 IAM 专家
关于你:
- 7 年以上身份、访问管理或平台安全工程经验
- 对 IAM 架构有深入理解,熟悉 AWS、Azure 或 GCP 等云平台的安全机制
查看英文原文
About Vercel:
Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.
About the Role:
We're looking for a Security Software Engineer to join our Security team and own Vercel's Identity and Access Management strategy - across both corporate and production environments. This is a high-impact, ownership-heavy role: you'll define IAM architecture from the ground up, migrate Okta fully behind Terraform, and serve as the subject matter expert who levels up the entire organization on IAM best practices.
You will report to the Head of Security and be located remotely within the United States. If you're based within commuting distance of our SF or NY offices, the role includes in-office anchor days on Monday, Tuesday, and Friday.
What You Will Do:
- Own the full IAM strategy for both corporate and production environments - defining the roadmap, standards, and architecture end to end
- Migrate Okta and all related IAM configuration to Terraform, driving infrastructure-as-code adoption and leveling up engineering teams in its use
- Lead Vercel-on-Vercel and Vercel infrastructure cleanup initiatives, ensuring our internal systems reflect the same standards we sell to customers
- Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure
- Partner with platform and engineering teams to embed IAM best practices early in the design process
- Build and manage MDM/MAM tooling to secure endpoint and mobile device access across the organization
- Drive automation across provisioning, deprovisioning, and access review workflows
- Serve as the IAM subject matter expert across Security, IT, and Engineering
About You:
- 7+ years of experience in identity, access management, or platform security engineering
- Deep expertise with Okta - including SSO, MFA, lifecycle management, and API-driven automation
- Proficient in Terraform and committed to managing IAM infrastructure as code
- Experience designing IAM strategy at scale - across both corporate (IT/SaaS) and production (cloud infrastructure) environments
- Hands-on experience with AWS or GCP IAM - service accounts, roles, workload identity federation
- Background in MDM/MAM solutions (Jamf, Intune, or equivalent)
- Strong collaborator who can drive alignment across Engineering, IT, Compliance, and Security teams
- Comfortable operating with autonomy and owning decisions in a fast-moving environment
Bonus If You:
- Experience leading Terraform migrations for IAM or identity infrastructure at scale
- Background in SCIM, SAML, OIDC, and directory services (e.g., Google Workspace, Azure AD)
- Contributions to internal developer platforms or security tooling
- Experience at a developer tools, infrastructure, or SaaS company
- Certifications such as Okta Certified Professional/Administrator, AWS Security Specialty, or CISSP
Benefits:
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $208,000 - $312,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.