Description
Overview of the Role:
We are looking for a Product Security Engineer to join our Salesforce Product Security Advisors team. You will be the technical authority responsible for assessing and providing remediation advice for the ecosystem that powers our clouds.
As a trusted security advisor, you'll serve as the primary point of contact for our engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions will directly shape and enhance the security posture of our core platforms, ensuring the resilience and integrity of Salesforce's offerings.
You'll sit at the intersection of application security and infrastructure, ensuring that every design decision follows thoughtful security principles and that implementation meets the highest security standards.
Responsibilities:
Embed security controls throughout the entire Software Development Life Cycle (SDLC), lead deep-dive threat modeling sessions for complex Salesforce Marketing Cloud (SFMC) integrations, and perform manual, agentic, and automated secure code reviews across Java, C#, PHP, and Python.
Conduct and coordinate penetration tests for high-risk features on internal and external-facing assets, and design and evaluate robust authentication and authorization (AuthN/AuthZ) frameworks including modern identity protocols such as Security Assertion Markup Language (SAML), OAuth 2.0, and OpenID Connect (OIDC).
Audit and harden cloud infrastructure supporting our environment, ensuring least-privilege access, resilient configurations, and adherence to security best practices.
Provide subject-matter expertise on identity management, email and messaging platform security, and Agentic AI, translating complex technical risks into clear business impact for engineering partners and leadership.
Required Qualifications:
5+ years in offensive or defensive security roles with a proven track record of securing enterprise-level cloud platforms, including expertise in OWASP Top 10 (Open Web Application Security Project) and SANS Top 25 (SysAdmin, Audit, Network, and Security).
Working knowledge of at least two of the following languages: Java, C#, PHP, or Python, plus familiarity with security tooling such as Snyk, Semgrep, GitHub Actions, Dynamic Application Security Testing (DAST), and Static Application Security Testing (SAST).
Strong communication skills with the ability to translate complex vulnerabilities such as heap-buffer overflows or Insecure Direct Object References (IDOR) into business risk that stakeholders can understand.
Curiosity and willingness to adopt AI tools to work smarter, deliver better results, and continuously grow technical knowledge.
Preferred Qualifications:
Offensive security certifications such as Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), or GIAC Web Application Pentester (GWAPT).
AWS Cloud Security Specialist or Google Cloud Platform (GCP) Cloud Security Expert certification.
Active participation in bug bounty programs (HackerOne, Bugcrowd) or contributions to open-source security tools and research.
Experience with the Salesforce ecosystem and applying AI tools such as Claude, Cursor, or Gemini to security assessments.
*LI-Y
For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.
