Senior Platform Trust and Safety Engineer

Salesforce · Washington - Bellevue · Bellevue

Spotted 1h agoFull time

What you'll need to apply

Fields this application requires

NameEmailPhoneCountryRésuméWork authorization answerVisa sponsorship answer

Company-specific questions

  • Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
  • Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
  • I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
  • Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
  • As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
  • Regarding future positions at Salesforce, please select one of the following options
  • I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
Job description

About this role

Employer-provided description, formatted for easier reading.

Salesforce's platforms — including Core CRM and Marketing Cloud — let companies build, deliver, monitor, and scale their engagement with customers globally. Not everyone uses that access responsibly. We're looking for a Platform Trust and Safety Engineer who is dedicated to identifying and stopping abusers who commit fraud, phishing, and account takeover, or who otherwise use our services to make the internet a hostile space.

The Platform Defense and Safety (PDS) team detects and responds to malicious user activity — misuse, abuse, fraud, and crime — that occurs even when our systems are working as designed. At any given time, bad actors attempt to bypass detection and response systems by posing as legitimate customers to take unfair advantage of our services.

Unlike account compromise, abuse tends to be a slow, simmering problem rather than a single event.

The Experience

  • Extensive experience in information security roles involving platform abuse, threat intelligence, incident response, or threat detection
  • Experience managing security or abuse investigations end to end: triage, evidence collection, risk assessment, containment, escalation, and closure
  • Specialization in at least one of: log analysis, file-level forensics, or data mining
  • Experience authoring detection rules using languages such as YARA or Splunk SPL, and comfort working from a command line

What You'll Actually Be Doing

  • Review, triage, and respond to external and internal abuse reports across Core CRM and Marketing Cloud, with an eye toward expanding into new products
  • Build and tune detection and response rules in Splunk, and author and maintain automated response playbooks
  • Partner with our Office of Ethical Usage and Legal teams — including on regulatory reporting such as the EU Digital Services Act (DSA) — to keep our platforms free of malicious content
  • Identify and document anti-abuse tooling requirements for engineering teams, and evaluate third-party vendor tools to close detection gaps

You're Our Person If...

  • You track emerging trends in digital crime, merchant fraud, and abuse of AI/agentic capabilities
  • You write and maintain clear playbooks, SOPs, and postmortems that drive continuous improvement
  • You collaborate easily across teams — including Product Security Advisors, engineering, and product teams — and can contribute to platform abuse threat modeling
  • You're comfortable participating in an on-call rotation

Even Better If...

  • You can quickly and effectively understand someone else's code
  • You have extensive experience using Splunk for detection engineering and SPL rule authoring
  • You've worked with threat intelligence tools or teams
  • You have experience with workflow orchestration or automation platforms (e.g., Temporal)
  • You've worked in a customer-facing role (Support, Sales Engineering, etc.)
  • You're familiar with evidence handling, privacy, data retention, and regulatory considerations relevant to security investigations
  • You understand cloud/SaaS security concepts, multi-tenant platforms, identity systems, and application telemetry
  • You have experience analyzing large, complex data sets, and familiarity with Git/GitHub and the Salesforce platform (Cases, SOQL)
Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce