Lead Threat Assessment Engineer

Salesforce · California - San Francisco · Bellevue · Palo Alto · San Francisco · Seattle

Spotted 1h agoFull time
Job description

About this role

Employer-provided description, formatted for easier reading.

The Experience

As a Lead Threat Assessment Engineer on the Environmental Threat Assessment team, you serve as an assessment lead and subject matter expert, supporting and building how we identify and mitigate threats across our global infrastructure.

You will not only execute complex threat assessments but also mentor a team of junior analysts and engineers, helping to scale our capabilities through automation and "agentic" security investments. Your work will directly shape Salesforce’s security posture by translating deep technical research into actionable requirements for Product & Enterprise Security partners and Product/Engineering stakeholders.

This role is within the Cybersecurity Operations Center vertical of Salesforce Security.

What You'll Actually Be Doing:

  • Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from an observed/realized threat and outside-in perspective.
  • Utilizing threat intelligence, incident response and detection telemetry, proprietary security tooling, and internal security and risk signals to correlate research and manage Salesforce’s top threats program.
  • Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls, across new and existing business units.
  • Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.
  • Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning.
  • Design and orchestrate new agentic tooling for the team analysis capabilities and projects, supported by frontier harnesses, org-specific skills, and human workflows.
  • Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing intelligence in Salesforce context in partnership with Threat Intelligence.
  • Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats.

You're Our Person If You Have:

  • 8+ years of experience in threat modeling and security architecture.
  • Significant understanding of threat actor tactics and offensive strategies and strong research and analytical skills with the ability to correlate data from various sources.
  • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE, and familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.
  • In-depth knowledge of cloud security and cloud architecture fundamentals and strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
  • Proficiency in analyzing logs from various security tools.
  • Excellent communication skills, both written and oral.
  • A related technical degree required.

Even Better If You Have:

  • Experience in Product or Enterprise Security design reviews and security assurance.
  • Experience automating processes and/or using AI tooling to automate workflows and data analysis.
Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce