Product Security Engineer
Confirmed live in the last 24 hours
Salesforce
Compensation
$117,200 - $194,200/year
Job Description
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
We are looking for a Product Security Engineer to join our Salesforce product security advisors team. You will be the technical authority responsible for assessing, and providing remediation advice for the ecosystem that power our clouds.
As a trusted security advisor, you'll serve as the primary point of contact for our engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions will directly shape and enhance the security posture of our core platforms, ensuring the resilience and integrity of Salesforce's offerings.
You’ll sit at the intersection of application security and infrastructure, ensuring that every design decision follows thoughtful security principles, and reviewing implementation that delivers it and meets the highest security standards.
Key Responsibilities
SDLC: Embed security controls throughout the entire SDLC, ensuring that "shifting left" is a reality, not just a buzzword.
Threat Modeling & Risk Assessment: Lead deep-dive threat modeling sessions for complex SFMC integrations and custom applications.
Code Review: Perform manual, agentic and automated secure code reviews across a diverse stack, including Java, C#, PHP, and Python.
Security Research & Pentesting: Conduct and Coordinate deep-dive penetration tests for high risk features on internal and external-facing assets.
Identity & Access Management: Design and evaluate robust AuthN/AuthZ frameworks in products. You’ll be our subject matter expert on modern Identity Management (IDM) protocols (SAML, OAuth2, OIDC), Agentic Identity and in email/messaging platform security.
Infrastructure Evaluation: Audit and harden the infrastructure supporting our cloud environment, ensuring least-privilege access and resilient configurations.
Required Qualifications
- The Experience: 5+ years in offensive or defensive security roles, with a proven track record of securing enterprise-level cloud platforms (Salesforce/SFMC experience is a massive plus but not a requirement).
- The Technical Breadth: Working knowledge of at least two of these languages: Java, C#, PHP, Python, knowledge of email/SMS threats and drive for continuous learning.
- The Mindset: You think like an attacker but build like an architect. You are passionate about breaking things to make them stronger.
- The Communication: You can translate a complex heap-buffer overflow or an IDOR into a business risk that a stakeholder can understand.
- AI Expertise: You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter and deliver better results.
- Expertise in OWASP Top 10 and SANS Top 25.
- Working knowledge of security tools (e.g., Snyk, Semgrep, GitHub Actions, DAST, SAST).
- A related technical degree required
Preferred Qualifications:
- Offensive Security: OSCP (Offensive Security Certified Professional), OSWE (Offensive Security Web Expert), or GWAPT (GIAC Web Application Pentester).
- Architecture & Cloud: AWS Cloud Security Specialist or GCP cloud security expert
- Active participation in Bug Bounty programs (HackerOne, Bugcrowd).
- Contributions to open-source security tools or research.
- Experience with the Salesforce ecosystem.
- Experience in applying AI innovations in security (Claude, Cursor, Gemini etc) to security assessments.
- Proficiency with pentesting frameworks.
Unleash Your Potential
When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.
Accommodations
If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.
Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.
Posting Statement
Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.
In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $117,200 - $176,700 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $141,200 - $194,200 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.Similar Jobs
Fiserv
Devops and Production Readiness Engineer
Fiserv
Devops and Production Readiness Engineer - 1
Amazon.com Services LLC
Security Engineer , Global Media and Entertainment Security
University Health
Specialist Product Design Verification Software Engineer Cybersecurity
Wells Fargo
Principal Engineer and Product Owner for Database Security Platform and Infrastructure Engineering
Palantir