Product Security Lead

Salesforce Salesforce · Enterprise · Bellevue, WA +1

Lead Penetration Testing Engineer for Salesforce's Security organization, focusing on offensive security and engineering partnership. The role involves executing deep penetration tests across applications, platforms, cloud infrastructure, and enterprise environments, with a specific emphasis on AI-powered features and systems, including LLM-backed applications and Agentic AI. Responsibilities include manual exploitation, prompt injection testing, and partnering with engineering teams to influence security design and guardrails.

What you'd actually do

  1. Lead and execute advanced penetration tests across web applications, APIs, cloud and hybrid infrastructure (Kubernetes, Docker), identity and authorization boundaries, internal and external enterprise attack surfaces, and AI/ML-enabled systems including large language model (LLM)-backed applications and Agentic AI.
  2. Perform manual exploitation beyond automated tooling, including business logic abuse, privilege escalation, identity and trust relationship abuse, and AI-specific offensive testing such as prompt injection and indirect prompt injection.
  3. Own engagements end to end — from scoping and test execution to risk assessment, clear reporting, and remediation guidance — developing deep technical understanding of systems to uncover systemic weaknesses, not just isolated bugs.
  4. Partner with engineering, security architecture, AppSec, and Detection and Response teams to explain root causes, influence design and guardrails, and produce high-quality reports that clearly articulate exploitation paths, missing security controls, and mitigation solutions.

Skills

Required

  • 5+ years of hands-on experience in penetration testing, offensive security, or vulnerability research, including leading complex engagements in production or production-like environments.
  • Strong understanding of application security vulnerabilities, identity and access control failures, cloud security, and security risks specific to AI and LLM-based systems.
  • Proven ability to perform manual exploitation and vulnerability chaining, develop custom scripts and proof-of-concept exploits, and work effectively with and beyond automated tooling.
  • Clear communication skills with the ability to articulate exploitation mechanics, business risk, and practical, prioritized remediation strategies to engineers, security teams, and leadership.

Nice to have

  • Offensive security certifications such as OSCP, OSEP, or equivalent.
  • Experience contributing to internal tooling, automation, or testing frameworks that improve scale or consistency without replacing deep manual testing.
  • Familiarity with detection and response concepts and how penetration testing findings intersect with monitoring and alerting.

What the JD emphasized

  • AI-specific offensive testing
  • prompt injection
  • indirect prompt injection
  • AI and LLM-based systems

Other signals

  • AI-powered features and systems
  • LLM-backed applications
  • Agentic AI