Enterprise Security Engineer, Senior & Lead (enterprise Security - Security Ai)

Salesforce Salesforce · Enterprise · San Francisco, CA +1

Salesforce is seeking a Senior/Lead Enterprise Security Engineer for their Secure AI team. This role focuses on assessing and maintaining the security of AI tooling, ensuring compliance with Salesforce security requirements for AI deployment at scale. Responsibilities include security assessments, threat modeling, developing automated security processes, defining security standards, and researching emerging AI threats and vulnerabilities. Experience with LLMs, agentic systems, and AI security attack surfaces is required.

What you'd actually do

  1. Lead by performing in-depth and high-quality security assessments of emerging technology (AI tooling, agentic platforms, etc.) including architecture and design reviews, code reviews, and penetration tests.
  2. Provide guidance to team members and prospective suppliers on Salesforce security requirements including remediation advice and potential feature enhancements.
  3. Research new technologies, emerging threats, and vulnerabilities for strategic planning and process improvements.
  4. Develop automated processes and support improvement of tooling to identify and solve problems at scale.
  5. Define and develop technical security standards and guidelines with business partners.

Skills

Required

  • 5+ years of experience in a security role (Senior)
  • Experience with large language models (LLMs) and agentic systems — building, evaluating, or securing them
  • Familiarity with AI security attack surfaces including prompt injection, data exfiltration, privilege escalation in agents, and model supply chain risks
  • Excellent interpersonal, collaboration, critical-thinking, and communication skills
  • A related technical degree required

Nice to have

  • Understanding of RAG architectures, classifier models, and how retrieval and generation pipelines work
  • Familiarity with security frameworks and certifications such as ISO 27001, SOC 2, PCI DSS, OWASP Top 10, CWE Top 25, and MITRE ATT&CK
  • Relevant BA/BS degree and/or certifications such as CRISC, CISSP, CCIE, CISM, CISA, or CCSK
  • Experience defining and communicating security remediation tasks to project and data owners
  • Ideally would have development background.

What the JD emphasized

  • security assessments of emerging technology
  • AI tooling
  • agentic platforms
  • security requirements
  • LLMs and agentic systems
  • AI security attack surfaces
  • prompt injection
  • data exfiltration
  • privilege escalation in agents
  • model supply chain risks

Other signals

  • security assessments of AI tooling
  • deploying AI at scale
  • experience with LLMs and agentic systems