Product Security Engineer (All Levels) at Salesforce.com in Bellevue, WA

Salesforce.com

๐Ÿ“Œ Bellevue, WA
๐Ÿ•‘ November 19, 2020
๐Ÿท๏ธ OTHER
View Application

You will be redirected to Salesforce.com's preferred application process.

Product Security Engineer (All Levels)

_To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts._ Job Category Products and Technology

Job Details

The Product Security team is responsible for the product security efforts for Salesforce products. We're looking for dedicated security engineers, who are subject matter experts in multiple security domains and are able to act as technical lead for strategic product security efforts, and are able to influence security direction of existing and new products. Lightning Platform Skills group is responsible for product security needs of several Products/Business Units including Core Salesforce UI, Sales Cloud, Service Cloud, Customer 360, Blockchain Platform, and more. We make ourselves available at every stage in the software development lifecycle, facilitating secure design choices without sacrificing the usability of our products. You'll own product security effort for several engineering teams within one or more business units. At this time we are looking for individuals with strong focus on Sales Cloud and Salesforce Core UI business units. You will work closely with our engineering teams to scope and execute application security reviews throughout the development cycle, including architecture reviews and threat models, secure code reviews, and platform and application penetration testing. You'll be expected to be an SME and lead strategic product security initiatives for all the products supported by the team, learn about multiple products, work with engineering architects, and product organization to build secure products. Key responsibilities
+ Influences and/or defines product security strategy for multiple business units and products.
+ Partners closely with engineering, and product organization to drive strategic security initiatives.
+ Act as a Subject Matter Expert for multiple security domains, and mentor junior team members to drive the strategic initiatives for you.
+ Scope and perform application security reviews of our full stack: web applications, AP
Is, and platform architectures.
+ Provide our engineers with well-researched security advice to demonstrate vulnerabilities and provide secure development guidance.
+ Assist in the triage of vulnerabilities that are found internally, privately or publicly disclosed, or reported through our bug bounty program.
+ Produce research and collaborate with our peers in the broader infosec and public cloud communities and industries.
+ Constantly question existing security practices and routines, and update, replace, or automate them.
+ Write and promote secure development practices for our engineers. Key competencies
+ Self-driven, passionate, and independent.
+ Strong influencer with a proven ability to build deep relationships and getting this done without authority.
+ Hands-on experience in driving the security efforts for multiple complex and large scale, cross-functional projects.
+ Be able to act as a multiplier via junior team members to accomplish more than the sum total of individual efforts.
+ Deep experience with performing threat modeling and architecture reviews.
+ Capability to look at the big picture/architecture and propose strategic security solutions.
+ Experience with black box, grey box, and white box security testing of applications, including manual secure code review.
+ Experience with public cloud infrastructure security protections and weaknesses
+ Strong working knowledge of web application development and architecture, HTTP, and TLS.
+ Scripting skills (our primary languages are Ruby, Python, Go, and Elixir, but we'll happily speak to candidates with other language backgrounds.)
+ Strong grasp of practical cryptography usage, able to recommend the best approach for storage, transport and identity purposes, specifically in the realm of public cloud.
+ Offensive mindset and the ability to think of and consider abuse and attack paths as well as the defensive mindset to think of recommendations to prevent them.
+ Enthusiastic and quick learning of complex systems and poorly-documented open source software.
+ Comfortable working with continuous integration/delivery and agile development teams. Technologies Strong candidates will have worked with some of these and/or similar technologies:
+ The UI Security role needs deep JavaScript and Browser Security understanding.
+ Application Security tools like Burp, OWASP ZAP, brakeman, and other DAST and SAST tools.
+ Security features in container and container orchestration technologies (LXC, Docker, Kubernetes, gvisor).
+ Languages - one or more of: Ruby, Python, Java, Go, Shell, JavaScript, both for performing code reviews and creating your own scripts and tooling (fuzzers, scanners, etc.).
+ Modern web technologies
- Ember.js, Angular, React
+ Redux, GraphQL, Socket.io/Websockets. _Salesforce, the Customer Success Platform and world's #1 CRM, empowers companies to connect with their customers in a whole new way. The company was founded on three disruptive ideas: a new technology model in cloud computing, a pay-as-you-go business model, and a new integrated corporate philanthropy model. These founding principles have taken our company to great heights, including being named one of Forbes's "World's Most Innovative Company" six years in a row and one of Fortune's "100 Best Companies to Work For" nine years in a row. We are the fastest growing of the top 10 enterprise software companies, and this level of growth equals incredible opportunities to grow a career at Salesforce. Together, with our whole Ohana (Hawaiian for "family") made up of our employees, customers, partners and communities, we are working to improve the state of the world._ Accommodations
- If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form. at Posting Statement At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at Salesforce and explore our at and at are Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. at and at do not accept unsolicited headhunter and agency resumes. at and at will not pay any third-party agency or company that does not have a signed agreement with at or .Salesforce welcomes all. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. Founded in 1999, Salesforce is the global leader in Customer Relationship Management (CRM). Companies of every size and industry are using Salesforce to transform their businesses, across sales, service, marketing, commerce, and more by connecting with customers in a whole new way. We harness technologies that can revolutionize companies, careers, and, hopefully, our world. Salesforce is built on a set of four core values: Trust, Customer Success, Innovation, and Equality. By making technology more accessible, we're helping create a future with greater opportunity and equality for all. This has taken our company to great heights, including being ranked by Fortune as one of the "Most Admired Companies in the World" and one of the "100 Best Companies to Work For" eleven years in a row, and named "Innovator of the Decade" and one of the "World's Most Innovative Companies" eight years in a row by Forbes. There are those who choose to work with the best and brightest. And then, there are those who want to do more than just a job. They are the ones improving lives, not only their careers. Having an impact now instead of later. Doing something that's so much bigger than themselves, an industry, and their company. We believe everyone can be a Trailblazer. Join Salesforce and discover a future of new opportunities.

View Application

You will be redirected to Salesforce.com's preferred application process.


Job Expires: December 19, 2020

More Angular Jobs



Uh oh! Something went wrong. Please try again.
We were unable to find any more job. Have you tried changing your search keywords?

ICYMI: Never Miss It Again!

You will be redirected to Salesforce.com's preferred application process.