Staff Security Software Engineer, Vulnerability Management - Slack

Salesforce Salesforce · Enterprise · Atlanta, GA +2

Staff Security Software Engineer focused on building and maintaining systems and tooling for vulnerability management at Slack. This role involves driving technical strategy for automation and scaling, integrating security tools, defining metrics, and mentoring engineers. Requires strong Python skills and experience in security engineering or infrastructure.

What you'd actually do

  1. Own the technical architecture and roadmap for vulnerability management tooling, including systems that automate identification, prioritization, tracking, and remediation of vulnerabilities across diverse ecosystems and environments.
  2. Lead the design and development of high-quality, scalable engineering solutions, balancing long-term maintainability with the practical needs of a fast-moving security organization.
  3. Drive integration strategy across vulnerability scanners, aggregation pipelines, and downstream systems, making principled decisions about data ownership, tool consolidation, and signal quality.
  4. Define and evolve the metrics and reporting frameworks the team uses to measure program effectiveness, moving the organization toward risk-based measurement rather than activity-based compliance tracking.
  5. Partner with cross-functional stakeholders including infrastructure, platform engineering, and product security teams to identify opportunities to embed security automation deeper into the development lifecycle.

Skills

Required

  • Python
  • security engineering
  • platform engineering
  • infrastructure-adjacent domains
  • end-to-end engineering projects
  • integrations with security tooling
  • CI/CD pipelines
  • version control workflows
  • modern software delivery practices
  • communication

Nice to have

  • Wiz
  • Tenable/Nessus
  • Twistlock
  • cloud environments
  • containerized environments
  • vulnerability management concepts
  • FedRAMP
  • DoD IL5/IL6
  • large-scale vulnerability aggregation systems
  • automated remediation workflows
  • AWS
  • Azure
  • GCP
  • containerized workloads

What the JD emphasized

  • U.S. Citizenship or Permanent Residency (Green Card holder). We are unable to provide visa sponsorship for this role.