Offensive Security Researcher

Salesforce · Israel - Tel Aviv · Tel Aviv

Spotted 2d agoFull time
Job description

About this role

We are looking for an Offensive Security Researcher with an attacker mindset to discover, analyze, and remediate security vulnerabilities across our products and platforms.

This role focuses on identifying root causes, architectural weaknesses, and recurring security anti-patterns, and implementing secure-by-default solutions that prevent vulnerabilities.

You will work alongside engineering teams to analyze design decisions, improve security posture, and support overall application security maturity.

Key Responsibilities

  • Conduct offensive security assessments (manual testing, code review, architectural analysis, threat modeling) across application ecosystems.
  • Identify critical, high-impact, and systemic vulnerabilities alongside isolated issues.
  • Perform security research to identify emerging attack vectors, abuse cases, and bypass techniques relevant to our applications and platforms.
  • Partner closely with software engineers, tech leads, and architects to:
  • Explain risk, impact, and exploitability.
  • Design and implement effective remediations.
  • Ensure fixes are scalable, maintainable, and aligned with engineering realities.
  • Execute Secure by Default initiatives by:
  • Applying security guardrails, patterns, and baseline controls.
  • Remediating insecure defaults and unsafe configurations.
  • Preventing vulnerabilities through platform-level and framework-level updates.
  • Review application and platform designs early in the development lifecycle to prevent vulnerabilities before release.
  • Apply security standards, best practices, and architectural guidance during application development.
  • Share security knowledge and offensive techniques with engineering teams.
  • Collaborate with detection, monitoring, and incident response teams to improve visibility into real-world exploitation.

Required Qualifications

  • 3+ years of experience in Application Security or Offensive Security with an attacker mindset.
  • Demonstrated experience finding and remediating vulnerabilities in complex applications.
  • Strong understanding of:
  • Web application security (OWASP Top 10 and beyond)
  • Authentication & authorization flaws
  • API security
  • Injection attacks, logic flaws, and access control bypasses
  • Secure design and threat modeling
  • Hands-on experience with manual security testing (beyond automated tools).
  • Ability to translate complex security findings into clear, actionable guidance for engineers.
  • Strong communication and collaboration skills with engineering teams.

Preferred Qualifications

  • Published security research or CVEs (technical blogs, advisories, whitepapers, or conference presentations).
  • Experience implementing platform-level or framework-level security improvements.
  • Background in vulnerability discovery, security research, or red teaming.
  • Experience implementing Secure by Default or security-by-design concepts.
  • Familiarity with cloud-native architectures, microservices, and distributed systems.
  • Ability to balance security requirements with product velocity and developer experience.

Benefits & Perks

Check out our benefits site which explains our various benefits, including wellbeing reimbursement, generous parental leave, adoption assistance, fertility benefits, and more.

Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce