Security Software Engineer, IAM
Job Description
<div class="content-intro"><h2>About Vercel:</h2> <p><span data-sheets-root="1">Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.</span></p> <p><span data-sheets-root="1">For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.</span></p> <p><span data-sheets-root="1">Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.</span></p> <p><span data-sheets-root="1">We are building the platform for that future, trusted by companies like <strong>OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide</strong>. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.</span></p></div><h2>About the Role:</h2> <p>We're looking for a<strong> </strong>Security Software Engineer to join our Security team and own Vercel's Identity and Access Management strategy - across both corporate and production environments. This is a high-impact, ownership-heavy role: you'll define IAM architecture from the ground up, migrate Okta fully behind Terraform, and serve as the subject matter expert who levels up the entire organization on IAM best practices.</p> <p>You will report to our Senior Engineering Manager, Security Operations and will be located remotely within the United States. If you're based within commuting distance of our SF or NY offices, the role includes in-office anchor days on Monday, Tuesday, and Friday.</p> <h2>What You Will Do:</h2> <ul> <li>Own the full IAM strategy for both corporate and production environments - defining the roadmap, standards, and architecture end to end</li> <li>Migrate Okta and all related IAM configuration to Terraform, driving infrastructure-as-code adoption and leveling up engineering teams in its use</li> <li>Lead Vercel-on-Vercel and Vercel infrastructure cleanup initiatives, ensuring our internal systems reflect the same standards we sell to customers</li> <li>Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure</li> <li>Partner with platform and engineering teams to embed IAM best practices early in the design process</li> <li>Build and manage MDM/MAM tooling to secure endpoint and mobile device access across the organization</li> <li>Drive automation across provisioning, deprovisioning, and access review workflows