Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Salesforce is seeking a senior security engineer to help secure a large enterprise software portfolio. You will work with product engineering teams to surface, validate, and prevent security vulnerabilities across code, APIs, and cloud services.
You will craft static analysis rules, extend agentic tooling, and influence risk decisions at the pull-request stage. Collaboration with leadership and product teams is essential.
Product
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Product Security at scale is changing. Frontier AI models can now reason about code the way skilled attackers do, and the security engineers who work alongside product teams have a new set of tools, a new set of threats, and a new set of decisions to make. This role sits at the center of that shift.
You will work directly with product engineering teams to find, validate, and prevent security vulnerabilities across a very large enterprise software portfolio. The engineering surface is broad: application code, cloud services, APIs, authentication and authorization systems, third-party dependencies. The tooling is evolving fast: agentic scanners, custom static analysis, dynamic validation, and detection engineering. You will be one of a small number of senior engineers whose judgment on what is real, what is exploitable, and what is worth fixing is trusted by product teams and by leadership.
Use agentic security systems, custom static analysis, manual review, and threat modeling to surface real risk. Every technique has failure modes; you know which one to reach for.
A finding is not a bug until someone shows it can actually be triggered. You will spend real time on validation; sometimes manually, sometimes by extending automated tooling to do more of the work. Reducing the manual validation cost of the program is an explicit engineering goal.
When a class of vulnerability shows up more than once, the answer is not to file the same bug thirty times. It is to author a static analysis rule that blocks the class at pull-request time.
You will contribute to the intake pipeline that graduates high-value findings into merge-blocking rules, and you will have opinions on which findings clear the rule-worthy bar and which do not.
Security consulting on hard architectural questions.
You will use and extend this scoping methodology across the products you work on.
Your impact is measurable - Detections shipped. Vulnerabilities closed. Systemic patterns eliminated.
When you join Salesforce, you'll be limitless in all areas of your life. Our benefits ...