Product Security
About this role
Employer-provided description, formatted for easier reading.
Member of Technical Staff, Product Security
About Our Team
Product Security secures the products and platforms that power Salesforce's customers. As a Member of Technical Staff on the Product Security team, you partner closely with product and engineering teams to understand product goals and requirements, identify security risks, and help scale security practices across the product lifecycle.
This role offers the opportunity to identify emerging threats in artificial intelligence (AI)-driven and agent-based products and to design security controls and processes that enable rapid, secure product innovation across Salesforce. This role is based in Seattle, WA or San Francisco, CA.
What You'll Actually Be Doing
- Conduct secure design reviews and threat modeling to proactively identify threats and translate them into prioritized mitigations and clear security requirements.
- Partner closely with product and engineering teams to design and implement security controls across distributed systems, including microservice architectures, cloud services, and platforms.
- Integrate shift-left security practices across the development lifecycle, from early design through production.
- Triage and drive remediation of findings from penetration tests, red team exercises, and bug bounty programs.
You're Our Person If...
- You have knowledge of evolving security risks affecting machine learning (ML) products, agent-based systems, and AI models and pipelines.
- You have a demonstrated adversarial mindset, with the ability to develop threat models and partner with engineering teams to reduce security risk.
- You have experience securing multi-cloud platforms and multi-tenant software as a service (SaaS) systems, including Kubernetes- and Docker-based environments.
- You have at least 3-5 years of experience in application, product, or security engineering, or a related technical security role.
Even Better If...
- You have hands-on experience exploiting AI/ML and generative AI (GenAI) security risks, including model poisoning, retrieval-augmented generation (RAG) data leakage, and runtime attack vectors.
- You have experience supporting offensive security programs, including bug bounties, red teaming, and penetration testing.
- You have given external presentations and/or developed open-source security projects or tools.