Lmts - Cybersecurity - Lead Threat Assessment Engineer - Hyderabad

Salesforce Salesforce · Enterprise · Hyderabad, India

Salesforce is seeking a Lead Threat Assessment Engineer to identify and mitigate threats across their global infrastructure. This role involves conducting threat modeling, assessing cloud security controls, analyzing security logs, and translating technical research into actionable recommendations for product and engineering teams. The position also involves mentoring junior analysts and scaling capabilities through automation and "agentic" security investments.

What you'd actually do

  1. Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from a realized threat and “outside-in” perspective.
  2. Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.
  3. Assessing cloud security controls and cloud architecture implementations across current businesses and future M&As, primarily across AWS, GCP, and Azure substrates.
  4. Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.
  5. Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.

Skills

Required

  • 9+ years of experience in threat modeling and security architecture.
  • Significant understanding of threat actor tactics and offensive strategies.
  • Strong research and analytical skills with the ability to correlate data from various sources.
  • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.
  • In-depth knowledge of cloud security and cloud architecture fundamentals.
  • Proficiency in analyzing logs from various security tools.
  • Familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.
  • Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
  • Excellent communication skills, both written and oral.

What the JD emphasized

  • agentic security investments
  • agentic era
  • AI agents
  • AI CRM