Product Security

Salesforce Salesforce · Enterprise · San Francisco, CA +1

Salesforce is seeking a Product Security Engineer to join their Product Security Advisors team. The role involves assessing and advising on the security of the ecosystem powering their AI CRM, acting as a technical authority and trusted security advisor to engineering partners and leadership. Responsibilities include embedding security controls throughout the SDLC, threat modeling, secure code reviews, penetration testing, auditing cloud infrastructure, and providing expertise on identity management, email security, and Agentic AI.

What you'd actually do

  1. Embed security controls throughout the entire Software Development Life Cycle (SDLC), lead deep-dive threat modeling sessions for complex Salesforce Marketing Cloud (SFMC) integrations, and perform manual, agentic, and automated secure code reviews across Java, C#, PHP, and Python.
  2. Conduct and coordinate penetration tests for high-risk features on internal and external-facing assets, and design and evaluate robust authentication and authorization (AuthN/AuthZ) frameworks including modern identity protocols such as Security Assertion Markup Language (SAML), OAuth 2.0, and OpenID Connect (OIDC).
  3. Audit and harden cloud infrastructure supporting our environment, ensuring least-privilege access, resilient configurations, and adherence to security best practices.
  4. Provide subject-matter expertise on identity management, email and messaging platform security, and Agentic AI, translating complex technical risks into clear business impact for engineering partners and leadership.

Skills

Required

  • 5+ years in offensive or defensive security roles
  • securing enterprise-level cloud platforms
  • OWASP Top 10
  • SANS Top 25
  • Java
  • C#
  • PHP
  • Python
  • security tooling
  • Snyk
  • Semgrep
  • GitHub Actions
  • DAST
  • SAST
  • communication skills
  • translate complex vulnerabilities into business risk

Nice to have

  • OSCP
  • OSWE
  • GWAPT
  • AWS Cloud Security Specialist
  • GCP Cloud Security Expert
  • bug bounty programs
  • HackerOne
  • Bugcrowd
  • open-source security tools and research
  • Salesforce ecosystem
  • AI tools
  • Claude
  • Cursor
  • Gemini

What the JD emphasized

  • technical authority
  • primary point of contact
  • trusted security advisor
  • deep-dive threat modeling sessions
  • agentic
  • Agentic AI