Search jobs > Atlanta, GA > Product security engineer

Senior Product Security Engineer

Salesforce
Atlanta, GA, United States
Full-time

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Software Engineering

Job Details

About Salesforce

We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way.

And, we empower you to be a Trailblazer, too driving your performance and career growth, charting new paths, and improving the state of the world.

If you believe in business as the greatest platform for change and in companies doing well and doing good you’ve come to the right place.

Slack enables people around the world to communicate and collaborate together, from the world’s largest public companies to the smallest of startups.

We take performance and reliability very seriously.

A taste of our scale :

During the week, our users spend over a billion minutes a day active in our product.

At peak usage, a million messages a minute passed through Slack.

Every day we see over 15 million simultaneously connected users

For millions of people, Slack is their primary communication tool for work and more, and they expect it to be extraordinarily reliable and fast year-round.

About Us

Our Product Security Assurance team supports the following tenet of Slack’s mission : make people’s working lives more secure.

We’re serious about protecting our infrastructure, operations, and most importantly our customers’ data. We take a systemic approach to security and strive to ensure we provide low friction, high impact security across everything we do.

As a member of the Product Security team, you care about shipping secure products and protecting Slack’s users from bad actors.

You are passionate about enabling our developers to deliver new features securely. You think about your job as not just identifying individual vulnerabilities but also finding effective ways to eliminate whole classes of them.

Your work will directly impact the way millions of people, teams, and businesses get things done using Slack.

Slack has a positive, diverse, and supportive culture we look for people who are curious, inventive, and working to be a little better every single day.

In our work environment, we aim to be smart, humble, hardworking and, above all, collaborative. If this sounds like a good fit for you, read on ahead!

What you will be doing

Contributing security-focused feedback to engineers during all phases of the development lifecycle

Performing technical security assessments on our web applications, native clients, internal services, and partner applications

Seeking out opportunities to automate processes when appropriate

Scaling the impact of our team through direct mentorship of our more junior team members

Communicating risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns

Maintaining and creating secure development practices and programs for our engineering teams and external developers

Acting as an ambassador for security within Slack

Serving as a public representative for security at Slack by engaging periodically in internal and external speaking engagements

Identifying emerging classes of vulnerabilities and developing solutions for them before they’re a problem

Efficiently scoping blackbox, whitebox, and graybox assessments to optimize security review time and resources

What you should have

Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required

4+ years proven experience in security testing of web applications and native apps including Electron and iOS and Android mobile applications.

Deep understanding of web application architecture and design principles

Experience with Threat Modeling applications using STRIDE or similar framework.

Experience with websockets and protobuf a plus

Strong written and verbal communication skills and ability to communicate with empathy when delivering constructive feedback regarding security matters to engineers and product designers

Experience with manual secure code review in languages such as : JavaScript, Java, Python, Ruby, PHP, HackLang

Familiarity with common web application testing tools for DAST, SAST, and IAST analysis such as Burp Suite, Snyk, and / or Semgrep

Knowledge of authentication mechanisms like SAML, OAuth, etc.

Knowledge of common security flaws and resolution as published by OWASP, SANS, etc.

Knowledge of how to test code and applications across various platforms (iOS, Mac, Linux, Windows, Android, etc) for security and quality

Ability to see patterns, commonalities and investigate complex issues

Organizational skills to bring together and record detailed and accurate information about bugs and systemic issues

Experience with Amazon AWS services and familiarity with Slack products is a plus

Current or former security training or certifications such as SANS GWAPT, OSCP, OSWE or similar is a plus

Public speaking engagements or published research is also a plus; a successful engineer in this role will be expected to represent Slack externally from time to time

Though this is not primarily a development role, some background in software engineering in a collaborative and dynamic environment is a plus

Accommodations

If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.

Posting Statement

At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces.

We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more.

Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.

Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.

Salesforce welcomes all.

1 hour ago
Related jobs
Promoted
ServiceNow
Atlanta, Georgia

As a Senior Staff Product Security Engineer, you will help security champions be successful. As a Senior Staff Product Security Engineer on the ServiceNow SSDL team, you will collaborate with developers and software architects on highly technical solutions and help the organization build secure and ...

Promoted
VirtualVocations
Marietta, Georgia

A company is looking for a Senior Product Engineer in the US. Key Responsibilities:Play a critical role in growing and evolving the web and mobile appBe a thought partner in building a product, company, and cultureOwn the full implementation of projects with autonomyRequired Qualifications:3+ years ...

Promoted
Bank of America Corporation
Atlanta, Georgia

You will work together with our Cloud Architects, Information Security, Technical Product Managers and Senior Stakeholders to ensure we are delivering the right solutions for our customers. We believe in high quality engineering culture to engineer our platforms with customer and platform mindset, d...

Promoted
VirtualVocations
Norcross, Georgia

Key Responsibilities:Support product teams in developing new features through security testing and code reviewsIdentify and address potential security vulnerabilities within applicationsLead efforts to enhance the secure software development life cycleRequired Qualifications:6+ years of software bui...

Promoted
Aon
Atlanta, Georgia

Support broking clients and potential new broking relationships through the evaluation of security programs and facilitating Aon proprietary assessment (CyQu) and ransomware evaluation report read-outs; conducting reviews of potential cybersecurity vulnerabilities; evaluating and analyzing appropria...

Promoted
VirtualVocations
Norcross, Georgia

A company is looking for a Senior Security Engineer, Blockchain. ...

Promoted
Confluent
Atlanta, Georgia

About the Role:We are looking for an experienced security engineer to join our cloud security team, and lead efforts in upleveling Confluent’s cloud security maturity. Perform security reviews and threat modeling of internal infrastructure and products for partner teams in Confluent Engineering. Doc...

Recruiters
Atlanta, Georgia
Remote

Senior Engineer - Generative AI Product Engineering (Remote-Eligible). We are committed to building world-class applied science and engineering teams and continue our industry leading capabilities with breakthrough product experiences and scalable, high-performance AI infrastructure. We are looking ...

JSC Nexus
Atlanta, Georgia

Primary Responsibility:This role will assist in evaluating, creating, and implementing security standards, processes, and procedures related to access control, application security, cloud security, endpoint security, and network security. Essential Functions:·       Performs information security ris...

Highmark Health
GA, Working at Home, Georgia

The Identity & Access Management Senior Security Engineer is responsible for acting as resource, leader, and peer coach with other engineers in the development, testing, implementation, and integration of Identity and Access Management systems and solutions. Experience working within an information ...