登录获取应用

职位 › Casablanca › 职位详情 2天前

Security Software Engineer, IAM

Vercel · Remote (Worldwide)

远程,全球均可英语

职位介绍

摘自雇主发布的职位信息 · Vercel · 发布于2026年10月8日

<p> <strong>Headquarters:</strong> Remote - United States </p> <div class="content-intro"><h2>About Vercel:</h2> <p><span>Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. For more than a decade we've helped builders move from idea to production with speed, security, and exceptional developer experience.</span></p> <p><span>Now we're scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.</span></p></div><h2>About the Role:</h2> <p>Traditional IAM teams operate as an approval queue: a request comes in, someone reviews it, grants it, and (hopefully) remembers to revoke it. Access reviews become quarterly spreadsheet exercises, audit evidence is assembled by hand, and the central team becomes the bottleneck for every decision. That model doesn't scale past a certain point, and Vercel is past it. Adding more approvers doesn't close the gap. Building the system that makes access self-serve, time-bound, and provable does.</p> <p>This role is about building that system. Identity at Vercel should work like the rest of our infrastructure: defined as code, reviewed in pull requests, deployed through CI, and observable in production. You'll own that transformation end to end: migrating Okta and all related IAM configuration fully behind Terraform, and building the self-serve access platform (including just-in-time access) that lets team and system owners define, request, and time-bound their own access instead of routing every decision through a central team. Provisioning, deprovisioning, and access reviews become workflows the system runs, with the audit evidence for SOC 2 and similar generated as a byproduct rather than a manual scramble.</p> <p>You'll also own the harder connective work: corporate IAM (employee identity, SaaS access, devices) and production IAM (service accounts, infrastructure permissions, on-call and prod access) usually live in separate silos with separate tools and separate evidence trails. You'll build them as one identity plane.</p> <p>And identity itself is changing shape. As agents increasingly act on behalf of users and systems, the old model of "one human, one identity" doesn't hold, and there's real debate about how to solve it: carry the human's identity through every hop the agent makes, or give the agent its own scoped identity that never impersonates the user. We don't have a fixed answer yet. We want someone who wants to be in the room helping us decide and then build it.</p> <p>Because of this, we're optimizing for someone who wants to build identity infrastructure as software, not administer identity products. A software engineer who's gone deep on identity, or an IAM engineer with a strong engineeri

提及的技能

DevOps

每个职位,都有你的匹配分

BabZituna按六个真实维度,将每个职位与你的资料对照评分,并告诉你为什么得出这个分数,公平性经过审计(阅读公开的偏见审计)。

获取应用 → ✓ 求职者100%免费
一个职位如何评分 示例
技能96经验90地点84工作方式74工作类型61薪资无数据

示例数据,并非真实候选人。每个维度根据你本人的资料按100分制评分;无法衡量的维度会如实标明,而不是猜测。