Mobile Security Engineer - Product Security

salesforce.com, inc.

Seattle (WA)

On-site

USD 117,200 - 176,700

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
Paid parental leave
401(k)
Employee stock purchasing program

Job summary

Salesforce.com, inc. is looking for a Mobile Security Engineer to protect the security of its mobile application portfolio. You will perform assessments on iOS and Android applications, manage mobile security tools, and guide engineering teams in security practices.

The ideal candidate has over 2 years of experience in application security, expertise in mobile security testing tools, and a related technical degree. This role offers a competitive salary and a comprehensive benefits package.

Qualifications

  • 2+ years in application security, mobile security testing, or mobile development.
  • Hands-on experience with mobile platform toolchain.
  • Familiarity with security testing tools.
  • Understanding of mobile authentication patterns.
  • Strong communication to explain mobile risks.

Responsibilities

  • Perform security assessments on mobile applications.
  • Manage mobile scanning platform across the app portfolio.
  • Conduct secure code reviews for mobile codebases.
  • Provide security guidance to engineering teams.
  • Build high-quality security tooling and automation.

Skills

Application security
Mobile security testing
iOS and Android platform security
Security testing tools
Communication skills
AI tools in development

Education

Related technical degree

Tools

Frida
Burp Suite
Xcode
Android Studio

Job description

The Experience

The Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile application portfolio – spanning many distinct apps and mobile Software Development Kits (SDKs) across iOS and Android for nearly every Cloud and acquisition. You'll be the dedicated technical owner for mobile application security testing, vendor‑managed mobile scanning platforms, and security design reviews for mobile features, working at the intersection of mobile platform security and product engineering. Your work will directly protect the apps that millions of customers interact with daily, from the Salesforce flagship app to Tableau Mobile, Field Service, Trailhead, and Mobile Publisher. Join a team committed to ensuring every mobile release ships with validated security controls and that runtime protection, authentication flows, and binary hardening meet the highest standards.

What You’ll Actually Be Doing
  • Perform manual and automated security assessments of iOS and Android applications, including binary reverse engineering, dynamic instrumentation, authenticated scanning, and review of OAuth/PKCE flows, certificate pinning implementations, and jailbreak/root detection controls.
  • Operate and expand the mobile scanning platform across the mobile app portfolio, manage pre‑production CI/CD pipeline integration, configure scanning rulesets, triage findings, and coordinate quarterly with external penetration testing vendors.
  • Conduct secure code reviews across Swift, Kotlin, Java, and React Native mobile codebases, embed security controls in mobile SDKs and feature development, and lead threat modeling sessions for mobile‑specific attack surfaces including on‑device AI, app attestation, and deep linking.
  • Provide mobile security guidance to engineering teams across all Clouds, translate mobile findings into actionable remediation, respond to customer compliance questionnaires, and serve as the mobile security subject‑matter expert for release planning and incident response.
  • Build and ship high‑quality, production‑grade security tooling and automation using modern engineering practices, with AI as a core part of your development workflow – pushing the boundaries of AI development tools to deliver secure, optimised, and high‑quality code.
  • Design and orchestrate complex systems where AI agents integrate seamlessly into security workflows, driving efficiency and innovation at scale.
  • Contribute to building and maintaining shared system context – an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably. Critically evaluate code (human‑ or AI‑generated) for correctness, quality, security, and performance.
You're Our Person If...
  • You have 2+ years in application security, mobile security testing, or mobile development with demonstrated knowledge of iOS and Android platform security models, the OWASP Mobile Top 10, and common mobile vulnerability classes.
  • You have hands‑on experience with the mobile platform toolchain (Xcode/Android Studio).
  • Familiarity with security testing tools such as Frida, NowSecure, objection, MobSF, Burp Suite, or commercial mobile SAST/DAST platforms.
  • You have an understanding of mobile authentication patterns (OAuth 2.0, PKCE, SAML), runtime protection mechanisms (code obfuscation, anti‑hooking, anti‑tampering), and app store ecosystem security considerations for both Apple and Google Play.
  • You have strong communication skills with the ability to explain mobile‑specific risks to engineering partners who may not have mobile security context.
  • You bring a demonstrated, genuine AI‑first approach to engineering – using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty.
  • You have experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor) in development workflows.
  • You have advanced prompt engineering skills and the ability to write precise, structured prompts and cultivate the system context that makes AI outputs reliable, secure, and production‑ready.
  • A related technical degree is required.
Even Better If...
  • You have experience evaluating mobile runtime protection tools such as Promon, DexGuard, or similar RASP solutions on jailbroken or rooted devices.
  • You hold mobile‑focused security certifications such as GIAC Mobile Device Security Analyst (GMOB), or general offensive certifications such as Offensive Security Certified Professional (OSCP) or Offensive Security Web Expert (OSWE) with demonstrated mobile testing experience.
  • You have active participation in mobile bug bounty programs (HackerOne, Bugcrowd), published mobile security research, CVE disclosures, or contributions to open‑source mobile security tools.
  • You have experience with mobile CI/CD pipelines, automated binary scanning integration, or familiarity with the Salesforce ecosystem and applying AI tools such as Claude, Cursor, or Gemini for security assessments.
Benefits and Compensation

In the United States, compensation offered will be determined by factors such as location, job level, job‑related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits.

Salesforce offers a variety of benefits to help you live well, including time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program.

In the San Francisco and New York City metropolitan areas, the base salary range for this role is $141,200 – $194,200 annually; otherwise the range is $117,200 – $176,700 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via the Accommodations Request Form.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants for employment. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law.

Unknown: Know your rights: workplace discrimination is illegal.

This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Mobile Security Engineer - Product Security
Mobile Security Engineer - Product Security

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 195,000
401(k)
Employee stock purchasing program
Medical, dental, and vision insurance
+1
Mobile Security Engineer - Product Security
Mobile Security Engineer - Product Security

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Medical, dental, vision insurance
Paid parental leave
Employee stock purchasing program
Mobile Security Engineer - Product Security
Mobile Security Engineer - Product Security

Salesforce • Seattle (WA)

On-site
USD 117,000 - 177,000
Mobile Security Engineer - Product Security
Mobile Security Engineer - Product Security

Salesforce, Inc. • San Francisco (CA)

Hybrid
USD 117,000 - 177,000
401(k)
Paid parental leave
Mental health support
Software Engineering SMTS
Software Engineering SMTS

salesforce.com, inc. • Bellevue (WA)

On-site
USD 148,000 - 224,000
Medical, dental, vision insurance
Paid parental leave
401(k) plan
+1
Software Security Engineer (Distributed Systems)
Software Security Engineer (Distributed Systems)

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 224,000
Medical insurance
Dental insurance
Employee stock purchase plan
Principal Software Developer, Platform Security
Principal Software Developer, Platform Security

Salesforce • San Francisco (CA)

On-site
USD 197,300 - 313,700
Time off programs
Medical, dental, vision insurance
Mental health support
+3
Enterprise Security Engineer, Senior & Lead (Enterprise Security - Security AI)
Enterprise Security Engineer, Senior & Lead (Enterprise Security - Security AI)

salesforce.com, inc. • Bellevue (WA)

On-site
USD 148,000 - 261,000
Medical, dental, and vision insurance
Time off programs
401(k) plan
Lead Security Consultant - Professional Services Security Assurance (PSSA)
Lead Security Consultant - Professional Services Security Assurance (PSSA)

salesforce.com, inc. • Town of Texas (WI)

On-site
USD 150,000 - 227,000
Lead Security Consultant - Professional Services Security Assurance (PSSA)
Lead Security Consultant - Professional Services Security Assurance (PSSA)

salesforce.com, inc. • Chicago (IL)

On-site
USD 150,000 - 227,000