Senior Threat Assessment Engineer

Salesforce Salesforce · Enterprise · San Francisco, CA +1

Salesforce is seeking a Senior Threat Assessment Engineer to conduct threat modeling, analyze security controls, and provide threat intelligence to shape the company's security posture. The role involves collaborating with various teams to identify and mitigate exploitable vectors, with a focus on cloud security and automation.

What you'd actually do

  1. Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture and interactions, and new products/features from a realized threat and “outside-in” perspective.
  2. Create onboarding strategy of all new M&As into Cyber Security Operations across assessments, log prioritization and onboarding, and detection and security tool validation.
  3. Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.
  4. Assessing cloud security controls and cloud architecture implementations across current businesses and future business units, primarily across AWS, GCP, and Azure substrates.
  5. Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.

Skills

Required

  • threat modeling
  • security architecture
  • log analysis
  • cloud security
  • application security
  • threat intelligence
  • Cyber Kill Chain
  • Diamond Model
  • MITRE ATT&CK
  • STRIDE

Nice to have

  • Product or Enterprise Security design reviews
  • security assurance
  • automating processes
  • AI tooling

What the JD emphasized

  • 6+ years of experience in threat modeling and security architecture.
  • Strong research and analytical skills with the ability to correlate data from various sources.
  • Proficiency in analyzing logs and events from various security tools like EDR, CSPM, SIEM, etc.
  • In-depth understanding of cloud security and application security fundamentals and best practices (such as OWASP Top 10).
  • Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
  • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.