Principal, Environmental Threat Assessment

Airkit

Airkit

San Francisco, CA, USA
Posted on Mar 17, 2026

Description

As a Principal Threat Assessment Engineer on the Environmental Threat Assessment team, you serve as a technical leader and subject matter expert, driving the strategic vision for how we identify and mitigate threats across our global infrastructure. You will not only execute complex threat assessments but also mentor a team of junior analysts and engineers, helping to scale our capabilities through automation and "agentic" security investments. Your work will directly shape Salesforce’s security posture by translating deep technical research into actionable requirements for Product & Enterprise Security partners and Product/Engineering stakeholders.

Your responsibilities will include:

  • Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from a realized threat and “outside-in” perspective.

  • Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.

  • Assessing cloud security controls and cloud architecture implementations across current businesses and future M&As, primarily across AWS, GCP, and Azure substrates.

  • Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.

  • Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.

  • Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning.

  • Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing threat intelligence in the Salesforce context in partnership with our Threat Intelligence team.

  • Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats.

Preferred Qualifications:

  • 10+ years of experience in threat modeling and security architecture.

  • Significant understanding of threat actor tactics and offensive strategies.

  • Strong research and analytical skills with the ability to correlate data from various sources.

  • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.

  • In-depth knowledge of cloud security and cloud architecture fundamentals.

  • Proficiency in analyzing logs from various security tools.

  • Familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.

  • Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.

  • Excellent communication skills, both written and oral.

  • A related technical degree required.

Preferred Qualifications:

  • Experience in Product Security, Security Assurance, etc
  • Ability to write automation and scripts and/or experience using AI tooling to do the same

For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.