Product Security Engineer | Vulnerability Response & Application Security

Salesforce Salesforce · Enterprise · Hyderabad, India

Salesforce is seeking a Product Vulnerability Engineer to join their security team. The role involves leading the response to lower/moderate severity vulnerabilities, participating in high-severity responses, managing and triaging security vulnerabilities, assessing complex problems, and investigating/analyzing vulnerabilities. The ideal candidate will have 3-7 years of experience in information security or related roles, with direct experience in security vulnerability response, familiarity with common security threats, application forensics skills, and strong technical fundamentals in networking, application protocols, system architecture, and software development. Experience with AI tools for automation and analysis is desired.

What you'd actually do

  1. Leading the response to lower/moderate severity vulnerabilities.
  2. Participating in the response to high-severity vulnerabilities.
  3. Managing and triaging security vulnerabilities, differentiating urgent issues from important ones.
  4. Assessing complex problems, formulating action plans, and driving resolution under pressure.
  5. Investigating and analyzing vulnerabilities to determine potential impact.

Skills

Required

  • information security
  • security vulnerability response
  • OWASP Top 10
  • common security threats
  • application forensics
  • Networking fundamentals
  • Common application protocols
  • System architecture
  • Basics of software development
  • web proxy tools
  • research and quickly learn unfamiliar technologies
  • Broad information security knowledge
  • key regulations and standards related to security vulnerability response

Nice to have

  • AI tools for automation and analysis
  • working in a large and complex organization
  • reproducing proof-of-concept exploitation steps
  • assessing vulnerability priority based on risk and impact
  • securing applications and infrastructure in Amazon Web Services
  • Deep application security knowledge
  • Relevant incident response or information security certifications

What the JD emphasized

  • direct experience in security vulnerability response
  • OWASP Top 10
  • Application forensics skills
  • Strong technical fundamentals
  • Broad information security knowledge