Product Security Engineer

Salesforce Salesforce · Enterprise · San Francisco, CA

Salesforce is seeking a Product Security Engineer to join their product security advisors team. The role involves assessing and providing remediation advice for the ecosystem powering their clouds, acting as a technical authority and trusted security advisor. Responsibilities include embedding security controls throughout the SDLC, threat modeling, code reviews, penetration testing, evaluating identity and access management, and auditing infrastructure. The role requires experience in offensive or defensive security, knowledge of programming languages, understanding of security tools, and expertise in OWASP Top 10 and SANS Top 25. While not requiring deep AI expertise, curiosity and willingness to adopt AI tools are expected. Experience applying AI innovations in security is preferred.

What you'd actually do

  1. Embed security controls throughout the entire SDLC, ensuring that "shifting left" is a reality, not just a buzzword.
  2. Lead deep-dive threat modeling sessions for complex SFMC integrations and custom applications.
  3. Perform manual, agentic and automated secure code reviews across a diverse stack, including Java, C#, PHP, and Python.
  4. Conduct and Coordinate deep-dive penetration tests for high risk features on internal and external-facing assets.
  5. Design and evaluate robust AuthN/AuthZ frameworks in products. You’ll be our subject matter expert on modern Identity Management (IDM) protocols (SAML, OAuth2, OIDC), Agentic Identity and in email/messaging platform security.

Skills

Required

  • 5+ years in offensive or defensive security roles
  • Working knowledge of at least two of these languages: Java, C#, PHP, Python
  • knowledge of email/SMS threats
  • Expertise in OWASP Top 10 and SANS Top 25
  • Working knowledge of security tools (e.g., Snyk, Semgrep, GitHub Actions, DAST, SAST)
  • A related technical degree

Nice to have

  • Salesforce/SFMC experience
  • OSCILLATOR (Offensive Security Certified Professional)
  • OSWE (Offensive Security Web Expert)
  • GWAPT (GIAC Web Application Pentester)
  • AWS Cloud Security Specialist
  • GCP cloud security expert
  • Active participation in Bug Bounty programs (HackerOne, Bugcrowd)
  • Contributions to open-source security tools or research
  • Experience with the Salesforce ecosystem
  • Experience in applying AI innovations in security (Claude, Cursor, Gemini etc) to security assessments
  • Proficiency with pentesting frameworks

What the JD emphasized

  • proven track record of securing enterprise-level cloud platforms
  • AI Expertise
  • AI innovations in security