Product Security Senior Penetration Tester

Salesforce Salesforce · Enterprise · San Francisco, CA

This role focuses on offensive security for AI systems, leading adversarial testing, developing security frameworks and tooling, and partnering with AI teams to mitigate risks. It involves testing AI/ML systems, understanding LLM vulnerabilities, and building automated testing frameworks.

What you'd actually do

  1. Lead adversarial testing by designing, scoping, and executing red team assessments across our AI ecosystem using a risk-based prioritization approach to discover and address vulnerabilities before they can be exploited.
  2. Innovate in AI attack techniques by combining cutting-edge academic research with proven offensive security methods to establish new Tactics, Techniques, and Procedures, and operationalize emerging research to keep assessments aligned with the state of the art.
  3. Build and scale security tooling using an automation-first philosophy, driving initiatives to shift security testing left by sharing purpose-built tools with AI security stakeholders across Engineering, Research, and Ethics.
  4. Serve as a strategic partner across the company, providing an offensive security perspective to guide product development, support corporate governance, and contribute to policies such as Salesforce's Generative AI Security Standard.

Skills

Required

  • 6+ years of experience in offensive security (red teaming, application security, penetration testing, vulnerability research, etc.)
  • 1+ years of direct, hands-on experience testing the security of AI/ML systems, with a deep understanding of LLM vulnerabilities
  • High degree of Python proficiency for tool development, assessment automation, and data analysis
  • Proven experience leading complex technical projects and/or mentoring security teams, with exceptional ability to communicate high-stakes technical risks to both engineering and executive audiences.

Nice to have

  • Advanced degree (MS or PhD) in a relevant field, or a public portfolio of security research including conference presentations, published papers, CVEs, or open-source contributions.
  • Experience creating or managing large-scale datasets for security testing or machine learning training.
  • Experience building automated testing frameworks or large-scale evaluation pipelines.
  • Familiarity with current AI safety research and frameworks like MITRE ATLAS and the OWASP Top 10 for LLMs.

What the JD emphasized

  • AI Security team
  • offensive security and artificial intelligence
  • testing the security of AI/ML systems
  • deep understanding of LLM vulnerabilities
  • building automated testing frameworks
  • large-scale evaluation pipelines

Other signals

  • AI Security team
  • offensive security and artificial intelligence
  • mitigate risk across all AI initiatives
  • developing novel security frameworks, specialized tooling, and foundational testing methodologies for both generative and predictive AI systems
  • adversarial datasets
  • in-house content generation systems
  • establishing Salesforce as a leader in the AI security field
  • Lead adversarial testing by designing, scoping, and executing red team assessments across our AI ecosystem
  • Innovate in AI attack techniques by combining cutting-edge academic research with proven offensive security methods
  • Build and scale security tooling using an automation-first philosophy
  • testing the security of AI/ML systems, with a deep understanding of LLM vulnerabilities
  • Experience building automated testing frameworks or large-scale evaluation pipelines