Product Security Engineer - All Levels
Salesforce
This job is no longer accepting applications
See open jobs at Salesforce .See open jobs similar to "Product Security Engineer - All Levels" Imagine.To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
Security Assurance works to ensure no significant security risk escapes into customer-facing products, the supporting infrastructure, or our enterprise technology stack by proactively scaling security practices at all stages of the engineering and development lifecycle.
Security Assurance supports our engineering teams on the full stack; from the application layer down, ensuring the security of our customer-facing products, and being security domain guides to engineering teams across Salesforce.
As part of the Secure Software development lifecycle, we play a critical role in conducting design and implementation assessments, performing application and infrastructure security reviews, penetration testing, researching security issues, building security tools, and offensive security engagements. We aim to identify and reduce risk across Salesforce.
Responsibilities.
- Ability to secure large, sophisticated enterprise architectures or systems deployed in public cloud
- Partner with engineering teams; performing threat modeling/data flow diagramming/architecture risk analysis, identifying security flaws, and driving work items and bugs from these activities to resolution
- Brainstorm with counterparts in the product teams to drive security improvements upstream. Identify the trade-offs of different solutions and recommend the optimal design to achieve both functional goals and security requirements
- Perform penetration testing and remediation activities. Work closely with developers throughout the SDLC to ensure their efforts are secure
- Build internal tools to improve our detection and prevention capabilities
- Develop secure code practices and provide hands-on training to engineering and operations
- Research new technologies, emerging threats, and vulnerabilities
- Perform innovative applied research on new attacks and present new findings to both internal and external audiences.
Skills and competencies:
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent training, fellowship, or work experience is required
- 4 + years of consistent proven track record in the following areas in a security engineering or research role:
- Hands-on knowledge of techniques, standards, and state-of-the-art capabilities for authentication and authorization, applied cryptography, data and communication protection, etc.
- Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
- Public Cloud security architecture and testing in one or more of the following: Amazon Web Services such as EC2, IAM, Lambda, ELB, ECS, S3, RDS, AWS Config, WAF, Shield, Cloudwatch, Macie, GuardDuty, Trusted Advisor, Support Plans, Security Hub, etc.
- In-depth understanding of application vulnerabilities, attack vectors and exploits, and techniques to remediate those vulnerabilities.
- Exploiting web and web services security vulnerabilities such as cross-site scripting, cross-site request forgery, SQL injection, DoS, XML/SOAP, API, etc.
- Experience with software development languages such as JavaScript, Java, C#, Python, and Solid knowledge of Web-related technologies.
- Technical knowledge of security topics across infrastructure security & application security domains
- Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth, and common security elements
- Possess the ability to communicate concisely, clearly, and thoughtfully to partners from a variety of backgrounds, including those who are non-technical.
Advantages:
- An attacker’s mindset; consider abuse and attack paths as well as the defensive approach to recommendations to prevent them
- A passion for improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.
- Reasonable understanding of cryptography and ability to recommend standard solutions for protecting data at rest and in storage, transport, and identity purposes
- Ability to work with data, identify trends, and propose comprehensive mitigations that eradicate systemic security concerns
- Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle
- Published CVEs, Public disclosures, and Informative research.
- Excellent report writing and presentation skills.
Benefits & Perks
Check out our benefits site which explains our various benefits, including wellbeing reimbursement, generous parental leave, adoption assistance, fertility benefits, and more.
Accommodations
If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.
Posting Statement
At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.
Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.
Salesforce welcomes all.
This job is no longer accepting applications
See open jobs at Salesforce .See open jobs similar to "Product Security Engineer - All Levels" Imagine.