4 days ago

Enterprise Application Security Engineer

Salesforce

On Site
Full Time
$194,200
Bellevue, WA

Job Overview

Job TitleEnterprise Application Security Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$194,200
LocationBellevue, WA

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

About Our Team

Enterprise Security secures our enterprise environment that serves our rapidly growing workforce! As a Senior Enterprise Application Security Engineer, you will partner closely with technology and business partners to understand their objectives, identify threats, and scale our enterprise security programs. You will collaborate with our Business and IT organizations and champion security requirements in the selection, development, and integration of a wide range of technologies. You will also have the opportunity to identify emerging threats and design new processes that balance security and business agility across Salesforce!

What You Will Be Doing

  • Perform full stack security assessments (such as architecture and design reviews, code reviews, and penetration tests) across a diverse and sophisticated range of environments including: Web applications/SaaS applications, Operating system and hardware platforms (server and client endpoints, mobile and other embedded devices), Network infrastructure (switches, routers, wireless access points, load balancers, firewalls, VPN, SDN, cloud), Authentication and authorization services (SAML, OAuth, Radius, Kerberos), Public cloud infrastructure platforms and technologies (AWS, GCP, Azure, Terraform), Middleware and API services.
  • Threat model common attacker methods to develop appropriate mitigation techniques, providing guidance that balances security requirements with functional requirements.
  • Develop automated processes and support improvement of tooling to identify and solve problems at scale.
  • Collaborate with engineering teams and business partners to drive solutions through a secure development lifecycle.
  • Define and develop technical security standards and guidelines with business partners.
  • Research new technologies, emerging threats, and vulnerabilities for strategic planning and process improvements.

What You Should Have

  • 2-4 years of experience in a security role with a focus on application and network security, penetration testing, security engineering, infrastructure engineering, threat modeling, red team operations, firewall/access control technologies, risk management, and/or endpoint security controls.
  • Knowledge of key areas pertaining to security such as common network security models and protocols, application security, methods of resolving integrity and providing confidentiality, operating systems internals and vulnerabilities, public key infrastructure and digital certificates, and exploit mitigation techniques.
  • Hands-on experience performing security assessments with common tools such as BurpSuite, Nexpose, Nessus, Metasploit, and Nmap.
  • Experience performing manual and tool-assisted code reviews (Java, JavaScript, Python, and other languages).
  • Experience designing solutions and/or performing security assessments in cloud environments (AWS, Azure, Google Cloud).
  • Excellent communication skills, with the ability to work as a team and collaborate effectively with diverse stakeholders.

Bonus Points

  • Confirmed scripting experience in one or more of these languages: Bash, PowerShell, Python, Java, JavaScript / NodeJS.
  • Security certification such as OSCP, OSEP, GCIH, GCIA, GPEN, GWAPT, GMOB, GPPA, CCNP, CCNP Security, CCIE Security.
  • Knowledge of development and security practices on the Salesforce platform, Heroku, Slack, Mulesoft, and/or Tableau.

Key skills/competency

  • Application Security
  • Penetration Testing
  • Threat Modeling
  • Cloud Security
  • Security Engineering
  • Code Review
  • Network Security
  • Risk Management
  • AWS
  • Scripting

Tags:

Enterprise Application Security Engineer
Application Security
Penetration Testing
Threat Modeling
Security Assessments
Code Reviews
Network Security
Risk Management
Vulnerability Management
Security Engineering
Incident Response
AWS
Azure
GCP
BurpSuite
Metasploit
Nmap
Nexpose
Nessus
Terraform
Python

Share Job:

How to Get Hired at Salesforce

  • Research Salesforce's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor, focusing on "Agentforce" and "Trailblazers".
  • Tailor your resume: Customize your resume to highlight experience in application security, penetration testing, cloud security (AWS, Azure, GCP), and threat modeling, using keywords from the job description.
  • Showcase relevant projects: Prepare to discuss hands-on experience with security assessments, code reviews (Java, Python, JavaScript), and tools like BurpSuite, Metasploit, and Nmap, emphasizing impact.
  • Master technical fundamentals: Demonstrate strong knowledge of network security models, application security vulnerabilities, exploit mitigation, and public key infrastructure during technical interviews.
  • Highlight collaboration and communication: Emphasize your ability to partner with engineering teams and business stakeholders to drive secure development lifecycles and define technical standards.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background