← Back to job listings
SA
Product Security Senior
Salesforce · Bellevue, United States
About The Role
Join our team as a Product Security Senior Engineer, where you will play a crucial role in addressing the evolving landscape of product security. You will work directly with product engineering teams to identify, validate, and prevent security vulnerabilities across a large enterprise software portfolio. Your expertise will be trusted by product teams and leadership, and your impact will be measurable through detections shipped, vulnerabilities closed, and systemic patterns eliminated.
- Collaborer directement avec les équipes d'ingénierie produit pour identifier, valider et prévenir les vulnérabilités de sécurité dans un large portefeuille de logiciels d'entreprise.
- Utiliser des systèmes de sécurité agentiques, une analyse statique personnalisée, une révision manuelle et une modélisation des menaces pour faire ressortir les risques réels.
- Contribuer à la pipeline d'admission qui fait passer les découvertes de haute valeur en règles bloquantes pour les fusions, et avoir des opinions sur les découvertes qui atteignent la barre des règles.
- Practical experience with at least one of: threat modeling, authentication and authorization design, cloud security architecture, or supply chain security
- Deep familiarity with at least one major language ecosystem (Java, Python, JavaScript/TypeScript, Go, Ruby, or similar) and the ability to read and reason about code in others
- A related technical degree required
- Excellent communication both written and verbal
- Working knowledge of static analysis tooling and how custom rules are authored, tuned, and maintained. Semgrep, CodeQL, or equivalent
- 5+ years in security engineering, application security, or a directly adjacent role. At least 2 of those years in a hands-on vulnerability-discovery capacity
- Comfort operating in ambiguity.; You should be able to scope your own work from a vague ask
- Hands-on experience with agentic security tooling — either using it, evaluating it, or building it. You should have opinions on where it works and where it does not
- Experience shipping custom static analysis rules that were actually adopted by developers, not just written
- Track record of finding vulnerabilities that mattered. Bug bounty history, CVE credits, or internal impact you can describe are all valid signals
- Experience partnering directly with product engineering teams as a security embed or consultant, not just as a scanner operator
- Prior work with authorization models at scale (RBAC, ABAC, tenancy-aware systems)
- Familiarity with the trade-off space between deterministic scanning (static analysis) and non-deterministic scanning (agentic tooling) — where each earns its place in a portfolio
- Contributions to open source security tooling, position papers, conference talks, or other public technical work
Similar roles you might like
See all →AL
Training Specialist
Aspire Living & Learning
$45,000 – 55,000/yrPosted today
AL
Special Education Teacher
Aspire Living & Learning
$65,000 – 95,000/yrPosted today
AL
Senior Behavior Therapist
Aspire Living & Learning
$40,000 – 50,000/yrPosted today
AL
Reading Specialist
Aspire Living & Learning
$70,000 – 95,000/yrPosted today
AL
Direct Support Professional (DSP) - Harford County
Aspire Living & Learning
$18/hrPosted today
AL
Direct Support Professional (DSP) - Bedford
Aspire Living & Learning
$18 – 19/hrPosted today
AL
Direct Support Professional (DSP) - Baltimore County
Aspire Living & Learning
$18/hrPosted today
AL
Direct Support Professional (DSP)
Aspire Living & Learning
$18Posted today
This is an external listing. JobSpring does not represent or verify the employer. Report this listing