Sr. Security Software Engineer, Vulnerability Management - Slack

Salesforce Salesforce · Enterprise · Atlanta, GA +2

Salesforce is seeking a Sr. Security Software Engineer for their Vulnerability Management team at Slack. The role involves building and maintaining systems and tooling for detecting, tracking, and remediating security vulnerabilities. Responsibilities include driving technical strategy for automation and scaling, integrating various security tools, and partnering with cross-functional teams to embed security into the development lifecycle. The ideal candidate has strong Python skills, experience in security or platform engineering, and a solid understanding of vulnerability management concepts.

What you'd actually do

  1. Contribute towards the technical architecture for vulnerability management tooling, including systems that automate identification, prioritization, tracking, and remediation of vulnerabilities across diverse ecosystems and environments.
  2. Design and develop of high-quality, scalable engineering solutions, balancing long-term maintainability with the practical needs of a fast-moving security organization.
  3. Drive integration strategy across vulnerability scanners, aggregation pipelines, and downstream systems, making principled decisions about data ownership, tool consolidation, and signal quality.
  4. Partner with cross-functional stakeholders including infrastructure, platform engineering, and product security teams to identify opportunities to embed security automation deeper into the development lifecycle.
  5. Identify systemic gaps and ambiguous, high-priority problems that cut across team boundaries, propose solutions, and drive them to completion with or without direct authority.

Skills

Required

  • Python
  • security engineering
  • platform engineering
  • infrastructure-adjacent domains
  • production-grade, tested, maintainable code
  • end-to-end engineering projects
  • vulnerability management concepts
  • integrations with security tooling
  • CI/CD pipelines
  • version control workflows
  • modern software delivery practices
  • working across teams
  • communicating technical concepts
  • strong judgment in the face of ambiguity

Nice to have

  • Wiz, Tenable/Nessus, Twistlock, or similar products
  • FedRAMP or DoD IL5/IL6
  • large-scale vulnerability aggregation systems
  • homegrown data pipelines
  • automated remediation workflows
  • cloud environments (AWS, Azure, GCP)
  • containerized workloads
  • open-source projects, published research, conference talks

What the JD emphasized

  • U.S. Citizenship or Permanent Residency (Green Card holder). We are unable to provide visa sponsorship for this role.