Senior/lead/principal Offensive Security

Salesforce Salesforce · Enterprise · Tel Aviv, Israel

Salesforce is seeking a Senior/Lead/Principal Offensive Security professional to join their Israel-based team. The role involves penetration testing, red teaming, and security research to identify and exploit vulnerabilities in Salesforce's products and infrastructure. Responsibilities include conducting advanced testing, developing custom tools, collaborating with product teams for remediation, and contributing to the offensive security program's maturity. Requires significant hands-on experience in offensive security, expertise in at least one domain (pen testing, red teaming, app security research, vulnerability discovery), strong programming skills, and a deep understanding of attack frameworks and vulnerability classes.

What you'd actually do

  1. Conduct advanced penetration testing, red team operations, or security research targeting Salesforce's cloud infrastructure, applications, and services
  2. Discover, exploit, and document security vulnerabilities using creative and methodical approaches
  3. Develop custom tools, exploits, and attack techniques to simulate real-world adversaries
  4. Collaborate with product teams to remediate vulnerabilities and improve secure design practices
  5. Contribute to the maturity of our offensive security program through automation, tooling, and process improvements

Skills

Required

  • offensive security
  • penetration testing
  • red teaming
  • application security research
  • vulnerability discovery
  • Python
  • Go
  • Bash
  • PowerShell
  • MITRE ATT&CK
  • OWASP
  • CWE

Nice to have

  • cloud security (AWS, GCP, Azure)
  • containerized environments (Kubernetes, Docker)
  • CI/CD pipeline security
  • supply chain attacks
  • infrastructure-as-code security
  • social engineering
  • physical security testing
  • adversary simulation
  • bug bounties
  • CTFs
  • conferences
  • open-source contributions
  • OSCP
  • OSCE
  • OSWE
  • GXPN

What the JD emphasized

  • 5+ years of hands-on experience in offensive security (Senior), 7+ years (Lead), or 10+ years (Principal)
  • Deep, demonstrable expertise in at least one of the following domains: penetration testing, red teaming, application security research, or vulnerability discovery, with strong foundational knowledge and willingness to learn across other offensive security disciplines
  • Proven ability to identify and exploit complex vulnerabilities in web applications, APIs, cloud environments, or infrastructure
  • Strong programming/scripting skills (e.g., Python, Go, Bash, PowerShell) for tooling and automation
  • Deep understanding of attack frameworks (MITRE ATT&CK), common vulnerability classes (OWASP, CWE), and exploitation techniques