Product Security Engineer

Leadout Capital

Palo Alto (CA)

On-site

USD 140,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Salesforce is seeking a Product Security Engineer, Infrastructure, to fortify security across our core infrastructure services and public cloud deployments. You will provide architectural security guidance to engineering teams responsible for foundational services, databases, and monitoring tools, ensuring resilient, compliant platforms.

You will work with BISOs, product teams, and security partners to shape risk-based security roadmaps, perform threat modeling, and champion secure SDLC

Qualifications

  • 3–5 years of security engineering/architecture or security assurance experience.
  • Experience securing cloud environments across major providers.
  • Experience with threat modeling and risk assessment across infra and app security.
  • Familiarity with OAuth/OIDC, SAML, and API authorization models.
  • Excellent written and verbal communication to influence engineers.

Responsibilities

  • Provide expert security advisory for large-scale cloud initiatives.
  • Lead threat modeling and risk mitigation throughout SDLC.
  • Collaborate with product teams to balance security and functionality.
  • Align security priorities with business risk with BISOs or equivalent.

Skills

Cloud security
Threat modeling
IAM & network security
Security advisory
Strong communication
Cloud architectures

Tools

Kubernetes
Docker
PKI tooling
SAST
CSPM
IaC security

Job description

Job Title: Product Security Engineer, Infrastructure

Job Category: Technology / Security

Location: San Francisco, CA or Bellevue, WA

The Experience

Join our Infrastructure Product Security Assurance team as a Product Security Engineer, where you play a pivotal role in fortifying the bedrock of Salesforce's entire product ecosystem. In this highly impactful position, you leverage deep technical expertise to provide strategic security guidance and leadership to engineering teams responsible for our foundational services, including technical controls, infrastructure databases, and monitoring tools across public cloud platforms.

As a trusted security engineer, you serve as the primary point of contact for engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions directly shape and enhance the security posture of our core infrastructure platforms, ensuring the resilience and integrity of Salesforce's offerings.

Our team specializes in providing deep architectural and infrastructure security expertise across a diverse range of technologies, both on-premises and in public cloud environments, including web applications, distributed systems, and virtualized infrastructures. You champion secure software development lifecycle (SSDL) best practices, empowering engineering teams to build secure products from the ground up.

What You'll Actually Be Doing
  • Provide expert security advisory for large-scale cloud initiatives, offering strategic guidance to engineering teams on complex enterprise architectures across the application and infrastructure stack.
  • Drive proactive security through architecture and threat modeling, partnering with engineering teams to identify vulnerabilities and develop risk mitigation plans throughout the software development lifecycle (SDLC).
  • Influence secure design and implementation by collaborating with product teams to recommend design solutions that balance functional goals with security requirements.
  • Align security priorities with business risk by working with Product Business Information Security Officers (BISOs) to curate and prioritize risk-based security initiatives, and by analyzing risk signals and emerging threats to shape security roadmaps.
You're Our Person If...
  • You have 3-5 years of experience in a security engineering, security architecture, or security assurance role.
  • Cloud Security: You have experience securing products and infrastructure across one or more public cloud environments (Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, or equivalent), with an understanding of cloud service models, shared responsibility boundaries, and identity primitives at scale.
  • Threat Modeling & Risk Assessment: You have experience conducting structured security design reviews and threat modeling across infrastructure and application security domains, with familiarity with common vulnerability classes (Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE) Top 25), and can evaluate and communicate security risk to technical and non-technical audiences alike.
  • Identity, Access, and Network Fundamentals: You understand authentication and authorization patterns including Open Authorization (OAuth) / OpenID Connect (OIDC), Security Assertion Markup Language (SAML), service-to-service authentication, and API authorization models, as well as TCP/IP, Transport Layer Security (TLS), network segmentation, and key management, certificate lifecycles, secrets handling, and encryption standards.
  • You have strong written and verbal communication skills, with the ability to influence engineering teams toward secure outcomes without relying on direct organizational authority.
Even Better If...
  • You can reason through abuse cases and attack paths, not just defensive recommendations, with some familiarity with penetration testing methodologies or offensive security techniques.
  • You have experience participating in or driving improvements to a secure development lifecycle, security review process, or security advisory program within an engineering organization.
  • You can work with structured data, identify patterns across a broad service portfolio, and propose mitigations that address root causes rather than individual findings.
  • You can read and reason about code in one or more languages common in cloud-native engineering environments - particularly Java, Go, or Python - and have hands‑on familiarity with container orchestration and workload security (Kubernetes, Docker, service mesh such as Istio), secrets/key management and Public Key Infrastructure (PKI) tooling, Cloud Security Posture Management (CSPM) and vulnerability scanning tools, or static analysis (SAST) and infrastructure-as-code security scanning.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer, Senior
Product Security Engineer, Senior

Leadout Capital • Palo Alto (CA)

On-site
USD 160,000 - 230,000
Product Security
Product Security

Leadout Capital • San Francisco (CA)

On-site
USD 150,000 - 190,000
Software Engineering MTS- Platform Security
Software Engineering MTS- Platform Security

Leadout Capital • San Francisco (CA)

On-site
USD 140,000 - 210,000
Principal Product Security Engineer
Principal Product Security Engineer

Leadout Capital • San Francisco (CA)

On-site
USD 180,000 - 260,000
Cloud & Infrastructure Security Engineer
Cloud & Infrastructure Security Engineer

salesforce.com, inc. • Bellevue (WA)

On-site
USD 117,000 - 177,000
Product Vulnerability Engineer
Product Vulnerability Engineer

Leadout Capital • McLean (VA)

On-site
USD 120,000 - 150,000
Senior Cloud Security Engineer, Infrastructure
Senior Cloud Security Engineer, Infrastructure

Salesforce • Palo Alto (CA)

On-site
USD 149,000 - 224,000
Product Security Engineer, Infrastructure
Product Security Engineer, Infrastructure

salesforce.com, inc. • San Francisco (CA)

On-site
USD 117,000 - 194,000
Cloud Security Architect — Product Infrastructure
Cloud Security Architect — Product Infrastructure

Salesforce • Palo Alto (CA)

On-site
USD 117,000 - 177,000
Senior Cloud Security Engineer, Infrastructure
Senior Cloud Security Engineer, Infrastructure

salesforce.com, inc. • Palo Alto (CA)

On-site
USD 149,000 - 224,000