Offensive Security Researcher
Core
Offensive Security Researcher with an attacker mindset to discover, analyze, and remediate security vulnerabilities across Salesforce products and platforms.
Role type
Senior IC offensive security researcher
Builds
Secure-by-default solutions, platform-level security guardrails, and architectural improvements for application ecosystems
Domain
SaaS / Cloud-native security
Required skills
offensive security assessments, manual security testing, code review, architectural analysis, threat modeling, vulnerability discovery, secure design, API security, authentication/authorization flaws, injection attacks, logic flaws, access control bypasses (via careerplan.io/jobs/JR362697-1-offensive-security-researcher-at-salesforce)
Preferred skills
published security research, CVEs, red teaming, secure-by-design concepts, cloud-native architectures, microservices, distributed systems
Responsibilities
Conduct offensive security assessments (manual testing, code review, architectural analysis, threat modeling) across application ecosystems; Identify critical, high-impact, and systemic vulnerabilities alongside isolated issues; Perform security research to identify emerging attack vectors, abuse cases, and bypass techniques; Partner with software engineers, tech leads, and architects to explain risk, impact, and exploitability; Design and implement effective remediations; Execute Secure by Default initiatives by applying security guardrails, patterns, and baseline controls; Review application and platform designs early in the development lifecycle to prevent vulnerabilities before release; Share security knowledge and offensive techniques with engineering teams; Collaborate with detection, monitoring, and incident response teams to improve visibility into real-world exploitation.
Seniority
Senior, hands-on IC
