Home
/
Software Engineering
/
Product Security Assurance Engineer - All Levels
Product Security Assurance Engineer - All Levels-September 2024
Atlanta
Sep 21, 2024
ABOUT SALESFORCE
Salesforce brings companies and customers together in the number one Customer Relationship Management platform.
10,000+ employees
Technology
VIEW COMPANY PROFILE >>
About Product Security Assurance Engineer - All Levels

  To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

  Job Category

  Product

  Job Details

  About Salesforce

  We're Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too - driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good - you've come to the right place.

  About Us

  Security Assurance works to ensure no significant security risk escapes into customer-facing products, the supporting infrastructure, or our enterprise technology stack by proactively scaling security practices at all stages of the engineering and development lifecycle.

  Security Assurance supports our engineering teams on the full stack; from the application layer down, ensuring the security of our customer-facing products, and being security domain guides to engineering teams across Salesforce.

  The Foundation & Acquisition & Security Focus Team is responsible for securing internal security and foundational services. This includes security controls and build infrastructure for all Salesforce products. As part of the Secure Software development lifecycle, we play a critical role in conducting design and implementation assessments, performing application and infrastructure security reviews, penetration testing, researching security issues, building security tools, and offensive security engagements. We aim to identify and reduce risk across Salesforce.

  Primary Responsibilities:

  Ability to secure large, sophisticated enterprise architectures or systems deployed in public cloudPartner with engineering teams; performing threat modeling / data flow diagramming / architecture risk analysis, identifying security flaws, and driving work items and bugs from these activities to resolutionBrainstorm with counterparts in the product teams to drive security improvements upstream. Identify the trade-offs of different solutions and recommend the optimal design to achieve both functional goals and security requirementsPerform penetration testing, infrastructure/vulnerability assessments, and remediation activities. Work with engineering teams throughout the SDLC to ensure their efforts are secureDevelop new automation and tooling to improve our detection and prevention capabilitiesDevelop secure code practices and provide hands-on training to engineering and operationsResearch new technologies, emerging threats, and vulnerabilitiesPerform innovative applied research on new attacks and present new findings to both internal and external audiences.

  Minimum Qualifications:

  Bachelor's degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required3 + years proven track record in the following areas in a security engineering or research role:Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS, XML/SOAP, API etc.Public Cloud security architecture and testing in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud etc.Experience with software development languages such as: JavaScript, Java, Python, Ruby, PHP, GoTechnical knowledge of security topics across infrastructure security & application security domainsUnderstanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elementsStrong writing and presentation skills. Possess the ability to communicate concisely, clearly, and thoughtfully to partners from a variety of backgrounds, including those who are non-technical.

  Preferred Qualifications:

  An attacker's mindset; consider abuse and attack paths as well as the defensive approach to recommendations to prevent themA passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.Reasonable understanding of cryptography and able to recommend standard solutions for protecting data at rest and in storage, transport and identity purposesAbility to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concernsExperience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycleSome experience performing penetration testing or familiarity with the process

  Accommodations

  If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.

  Posting Statement

  At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.

  Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.

  Salesforce welcomes all.

  Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

  For Washington-based roles, the base salary hiring range for this position is $146,600 to $237,200.

  For California-based roles, the base salary hiring range for this position is $160,000 to $258,700.

  Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: https://www.salesforcebenefits.com.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Software Engineer - Full Stack
OVERVIEW This position can be based out of San Francisco or New York City We're looking for Full-Stack Software Engineers to join our Engineering team. In this role, you will build innovative payment
Software Engineer - Card Processing and Authorisation
Company Description Checkout.com is one of the most exciting FinTechs in the world. Our mission is to enable businesses and their communities to thrive in the digital economy. We’re the strategic pay
Site Reliability Engineer
At Broadridge, we've built a culture where the highest goal is to empower others to accomplish more. If you're passionate about developing your career, while helping others along the way, come join t
Software Engineer (Hybrid)
Software Engineer - IE08DE We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to
Sr. Manager, Analytics Engineer - Biopharma
ROLE SUMMARY: Pfizer is seeking hardworking, passionate and results-oriented individuals to join our Analytics Engineering team to build data foundations and tools to craft the future. You will desig
Engineering Manager - Corlu IC
ABOUT UNILEVER With 3.4 billion people in over 190 countries using our products every day, Unilever is a business that makes a real impact on the world. Work on brands that are loved and improve the
Lagerleiter*in (d/w/m)
DU BIST MEHR ALS DEIN JOB-TITEL. MEHR ALS ZAHLEN UND BUCHSTABEN IN DEINEM LEBENSLAUF. UND WIR SIND MEHR ALS EIN UNTERNEHMEN. WIE WÄR'S ALSO, WENN WIR UNS EINFACH ZUSAMMENTUN - UND GEMEINSAM NOCH MEHR
Software Developer in Test - Vice President
iCapital is powering the world’s alternative investment marketplace. Our financial technology platform has transformed how advisors, wealth management firms, asset managers, and banks evaluate and re
Senior Software Engineer, Experience Containerization
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers a
Staff Software Engineer - Backend (Growth Data Platform Team)
Hinge Health is creating a new health care system, built around you. Accessible to 26 million members across 1,500 customers, Hinge Health is the #1 digital clinic for joint and muscle pain, deliveri
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved