Principal Security Researcher
Spotted 1h agoFull time
Job description
About this role
Employer-provided description, formatted for easier reading.
The Experience
The Security Research team is Salesforce's offensive security engine, hunting for real-world attack paths across our products and infrastructure before adversaries do. We're looking for a Principal Security Researcher , based in Israel, to bring deep offensive security expertise, autonomy, and a relentless attacker mindset to help drive lasting security improvements at scale.
What You'll Actually Be Doing
- Lead advanced penetration testing, red team operations, or security research against Salesforce's cloud infrastructure, applications, and services, uncovering vulnerabilities that matter most
- Build custom tools, exploits, and attack techniques that simulate real-world adversaries and raise the bar for our offensive security tradecraft
- Partner with product teams to translate offensive findings into remediation and stronger secure design practices
- Mentor team members and present findings to technical and executive audiences, growing the team's overall offensive security capability
You're Our Person If...
- You have 10+ years of hands-on experience in offensive security, with deep, demonstrable expertise in at least one of: penetration testing, red teaming, application security research, or vulnerability discovery
- You've identified and exploited complex vulnerabilities in web applications, APIs, cloud environments, or infrastructure
- You have strong programming or scripting skills (Python, Go, Bash, PowerShell) for tooling and automation, and a solid grasp of attack frameworks (MITRE ATT&CK) and vulnerability classes (OWASP, CWE)
- Degree or equivalent relevant experience required. Experience will be evaluated based on the core competencies for the role (e.g. extracurricular leadership roles, military experience, volunteer roles, work experience, etc.)
Even Better If...
- You have experience in cloud security (AWS, GCP, Azure) or containerized environments (Kubernetes, Docker)
- You've contributed to CVE discoveries, security tooling, or CI/CD and supply chain security
- You're active in the security community (bug bounties, CTFs, conferences, open-source contributions)
- You hold relevant certifications (OSCP, OSCE, OSWE, GXPN, or equivalent)
Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce