Jobs / United States / Vercel INC
Security Software Engineer, IAM
Vercel INC · 🇺🇸 Remote - United States · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 10 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Vercel INC paid sponsored hires in similar roles3 certified filings for “Software Engineer” (Software Developers) in CA: $184k–$245k, median $202k. Most were filed at wage level II (67%) — 2 lottery entries, ≈31% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Vercel INC
The US Department of Labor certified 10 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Vercel INC →
About the role
About Vercel: Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. For more than a decade we've helped builders move from idea to production with speed, security, and exceptional developer experience. Now we're scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. About the Role: Traditional IAM teams operate as an approval queue: a request comes in, someone reviews it, grants it, and (hopefully) remembers to revoke it. Access reviews become quarterly spreadsheet exercises, audit evidence is assembled by hand, and the central team becomes the bottleneck for every decision. That model doesn't scale past a certain point, and Vercel is past it. Adding more approvers doesn't close the gap. Building the system that makes access self-serve, time-bound, and provable does. This role is about building that system. Identity at Vercel should work like the rest of our infrastructure: defined as code, reviewed in pull requests, deployed through CI, and observable in production. You'll own that transformation end to end: migrating Okta and all related IAM configuration fully behind Terraform, and building the self-serve access platform (including just-in-time access) that lets team and system owners define, request, and time-bound their own access instead of routing every decision through a central team. Provisioning, deprovisioning, and access reviews become workflows the system runs, with the audit evidence for SOC 2 and similar generated as a byproduct rather than a manual scramble. You'll also own the harder connective work: corporate IAM (employee identity, SaaS access, devices) and production IAM (service accounts, infrastructure permissions, on-call and prod access) usually live in separate silos with separate tools and separate evidence trails. You'll build them as one identity plane. And identity itself is changing shape. As agents increasingly act on behalf of users and systems, the old model of "one human, one identity" doesn't hold, and there's real debate about how to solve it: carry the human's identity through every hop the agent makes, or give the agent its own scoped identity that never impersonates the user. We don't have a fixed answer yet. We want someone who wants to be in the room helping us decide and then build it. Because of this, we're optimizing for someone who wants to build identity infrastructure as software, not administer identity products. A software engineer who's gone deep on identity, or an IAM engineer with a strong engineering background, is exactly who we're looking for. You'll work closely with Security Leadership, located remotely within the United States. If you're based within commuting distance of our SF or NY offices, the role includes in-office anchor days on Monday, Tuesday, and Friday. What You Will Do: • Own the full IAM strategy for corporate, production, and product environments end to end, and own the bridge between corp IAM and product/prod IAM rather than treating them as separate problems • Migrate Okta and all related IAM configuration to Terraform , so every identity change is reviewed, tested, and versioned like the rest of our infrastructure, driving infrastructure-as-code adoption and leveling up engineering teams in its use • Build self-serve access governance tooling, including JIT (just-in-time) access: design and ship the framework that lets team and system owners define, request, and time-bound their own access, rather than security being a bottleneck for every request • Own provisioning, deprovisioning, and access review workflows , built so the evidence trail generates itself and internal and external audi