Product Security
Core
Technical authority responsible for assessing and providing remediation advice for the ecosystem powering Salesforce's core cloud platforms.
Role type
Product Security Engineer (Application & Infrastructure Security)
Builds
Security posture of Salesforce's core cloud platforms (Marketing Cloud, etc.)
Domain
Cloud Security / Application Security / Identity Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Offensive/defensive security, OWASP Top 10, SANS Top 25, Java/C#/PHP/Python, Snyk, Semgrep, GitHub Actions, DAST, SAST, AuthN/AuthZ frameworks (SAML, OAuth 2.0, OIDC), cloud infrastructure hardening, identity management, Agentic AI security
Preferred skills
OSCP, OSWE, GWAPT, AWS Cloud Security Specialist, GCP Cloud Security Expert, bug bounty participation, open-source security contributions, Salesforce ecosystem experience, AI tool usage (Claude, Cursor, Gemini)
Technologies
Java, C#, PHP, Python, Snyk, Semgrep, GitHub Actions, SAML, OAuth 2.0, OpenID Connect, AWS, GCP, Salesforce Marketing Cloud
Responsibilities
Embed security controls in SDLC, lead threat modeling for complex integrations, perform secure code reviews, conduct penetration tests, design/evaluate AuthN/AuthZ frameworks, audit/harden cloud infrastructure, provide SME on identity/AI security
Seniority
Mid-Senior, hands-on IC