Penetration Testing Engineer, MTS

Salesforce · California - Remote · Bellevue · Herndon · Remote

Spotted 1h agoFull time
Job description

About this role

Employer-provided description, formatted for easier reading.

Penetration Testing Engineer, MTS

The Experience

We are looking for a Penetration Testing Engineer to execute deep, hands-on penetration tests across our applications, platforms, cloud infrastructure, and AI-powered systems. You'll bring a hacker mindset to real exploitation and attack chaining rather than checklist-driven testing, working under the guidance of senior team members on complex engagements.

You'll partner with engineering and AppSec teams to turn findings into concrete remediation, while building your skills across cloud, identity, and AI/ML attack surfaces.

What You'll Actually Be Doing

  • Execute penetration tests across web applications, APIs, cloud/hybrid infrastructure (Kubernetes, Docker), identity and trust boundaries, and AI/ML-enabled systems, including prompt injection and abuse of AI integrations.
  • Perform manual exploitation beyond automated tooling, including business logic abuse, privilege escalation, and identity/access trust relationship abuse.
  • Support engagements through scoping, execution, risk assessment, and clear reporting with remediation guidance.
  • Produce technically detailed reports covering exploitation paths, missing security controls, and mitigation recommendations, and collaborate with engineering, AppSec, and Detection & Response teams on findings.

You're Our Person If...

  • You have 2-4 years of hands-on experience in penetration testing, offensive security, or application security testing.
  • You have experience performing penetration testing engagements in production or production-like environments, using manual techniques and automation/AI tools.
  • You understand application security vulnerabilities and attack chains, identity and access control failures, cloud security fundamentals, and security risks specific to AI and LLM-based systems.
  • You can clearly articulate exploitation mechanics, impact, and practical remediation steps to engineers and security teams.

Even Better If...

  • You have experience with custom scripts, payloads, or proof-of-concept development.
  • You've participated in Bug Bounty programs.
  • You're familiar with cloud architectures and identity-centric security models.
  • You have experience using AI/LLMs for offensive security work or vulnerability discovery.
Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce