Skip to content
← Back to job listings

Product Security Senior

Salesforce · Bellevue, United States

Imported listingfull-timeabout 1 month ago

About The Role

Join our team as a Product Security Senior Engineer, where you will play a crucial role in addressing the evolving landscape of product security. You will work directly with product engineering teams to identify, validate, and prevent security vulnerabilities across a large enterprise software portfolio. Your expertise will be trusted by product teams and leadership, and your impact will be measurable through detections shipped, vulnerabilities closed, and systemic patterns eliminated.

  • Collaborer directement avec les équipes d'ingénierie produit pour identifier, valider et prévenir les vulnérabilités de sécurité dans un large portefeuille de logiciels d'entreprise.
  • Utiliser des systèmes de sécurité agentiques, une analyse statique personnalisée, une révision manuelle et une modélisation des menaces pour faire ressortir les risques réels.
  • Contribuer à la pipeline d'admission qui fait passer les découvertes de haute valeur en règles bloquantes pour les fusions, et avoir des opinions sur les découvertes qui atteignent la barre des règles.
  • Practical experience with at least one of: threat modeling, authentication and authorization design, cloud security architecture, or supply chain security
  • Deep familiarity with at least one major language ecosystem (Java, Python, JavaScript/TypeScript, Go, Ruby, or similar) and the ability to read and reason about code in others
  • A related technical degree required
  • Excellent communication both written and verbal
  • Working knowledge of static analysis tooling and how custom rules are authored, tuned, and maintained. Semgrep, CodeQL, or equivalent
  • 5+ years in security engineering, application security, or a directly adjacent role. At least 2 of those years in a hands-on vulnerability-discovery capacity
  • Comfort operating in ambiguity.; You should be able to scope your own work from a vague ask
  • Hands-on experience with agentic security tooling — either using it, evaluating it, or building it. You should have opinions on where it works and where it does not
  • Experience shipping custom static analysis rules that were actually adopted by developers, not just written
  • Track record of finding vulnerabilities that mattered. Bug bounty history, CVE credits, or internal impact you can describe are all valid signals
  • Experience partnering directly with product engineering teams as a security embed or consultant, not just as a scanner operator
  • Prior work with authorization models at scale (RBAC, ABAC, tenancy-aware systems)
  • Familiarity with the trade-off space between deterministic scanning (static analysis) and non-deterministic scanning (agentic tooling) — where each earns its place in a portfolio
  • Contributions to open source security tooling, position papers, conference talks, or other public technical work

This is an external listing. JobSpring does not represent or verify the employer. Report this listing