Product Security
Listed on 2026-06-06
-
IT/Tech
Cybersecurity, IT Consultant
Product Security Engineer – part of Salesforce Product Security Advisors team.
Overview OfThe Role
We are looking for a Product Security Engineer to join our Salesforce Product Security Advisors team. You will be the technical authority responsible for assessing and providing remediation advice for the ecosystem that powers our clouds. As a trusted security advisor, you’ll serve as the primary point of contact for our engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations.
You’ll sit at the intersection of application security and infrastructure, ensuring that every design decision follows thoughtful security principles and that implementation meets the highest security standards.
- Embed security controls throughout the entire Software Development Life Cycle (SDLC), lead deep‑dive threat modeling sessions for complex Salesforce Marketing Cloud (SFMC) integrations, and perform manual, agentic, and automated secure code reviews across Java, C#, PHP, and Python.
- Conduct and coordinate penetration tests for high‑risk features on internal and external‑facing assets, and design and evaluate robust authentication and authorization (AuthN/AuthZ) frameworks including modern identity protocols such as Security Assertion Markup Language (SAML), OAuth 2.0, and OpenID Connect (OIDC).
- Audit and harden cloud infrastructure supporting our environment, ensuring least‑privilege access, resilient configurations, and adherence to security best practices.
- Provide subject‑matter expertise on identity management, email and messaging platform security, and Agentic AI, translating complex technical risks into clear business impact for engineering partners and leadership.
- 5+ years in offensive or defensive security roles with a proven track record of securing enterprise‑level cloud platforms, including expertise in OWASP Top 10 (Open Web Application Security Project) and SANS Top 25 (Sys Admin, Audit, Network, and Security).
- Working knowledge of at least two of the following languages:
Java, C#, PHP, or Python, plus familiarity with security tooling such as Snyk, Semgrep, Git Hub Actions, Dynamic Application Security Testing (DAST), and Static Application Security Testing (SAST). - Strong communication skills with the ability to translate complex vulnerabilities such as heap‑buffer overflows or Insecure Direct Object References (IDOR) into business risk that stakeholders can understand.
- Curiosity and willingness to adopt AI tools to work smarter, deliver better results, and continuously grow technical knowledge.
- Offensive security certifications such as Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), or GIAC Web Application Pentester (GWAPT).
- AWS Cloud Security Specialist or Google Cloud Platform (GCP) Cloud Security Expert certification.
- Active participation in bug bounty programs (Hacker One, Bugcrowd) or contributions to open‑source security tools and research.
- Experience with the Salesforce ecosystem and applying AI tools such as Claude, Cursor, or Gemini to security assessments.
Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program.
Posting StatementSalesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal.
Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).