Senior/Lead/Principal Offensive Security

Salesforce
Tel Aviv
Workplace: HybridFull timeFunction: Research & Scientific (R&D)Experience: 5+ yearsSkills: ["Communication","Collaboration","Mentoring","Problem-solving"]

Lead offensive security research across Salesforce applications, driving discovery of systemic vulnerabilities, root-cause analysis, and secure-by-default remediations. Partner with engineers to influence design decisions, mentor security staff, and raise security maturity at scale. Focus on preventing classes of vulnerabilities through platform-level guardrails, threat modeling, and early security guidance in the development lifecycle.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
5 months ago

Senior/Lead/Principal Offensive Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Lead offensive security research across Salesforce applications, driving discovery of systemic vulnerabilities, root-cause analysis, and secure-by-default remediations. Partner with engineers to influence design decisions, mentor security staff, and raise security maturity at scale. Focus on preventing classes of vulnerabilities through platform-level guardrails, threat modeling, and early security guidance in the development lifecycle.
Location: Tel Aviv
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)

Key Responsibilities

  • •Lead offensive security assessments across complex application ecosystems (manual testing, code review, architectural analysis, threat modeling).
  • •Discover critical, high-impact, and systemic vulnerabilities rather than isolated issues.
  • •Conduct security research to identify emerging attack vectors, abuse cases, and bypass techniques relevant to our applications and platforms.
  • •Partner with software engineers, tech leads, and architects to clearly explain risk, impact, and exploitability; design and implement effective remediations; ensure fixes are scalable and maintainable.
  • •Drive Secure by Default initiatives by defining security guardrails, patterns, and baseline controls; eliminating insecure defaults and unsafe configurations; preventing future vulnerabilities through platform-level changes.

Key Requirements

  • •5+ years of deep experience in Application Security with a strong offensive mindset.
  • •Proven experience finding critical and systemic vulnerabilities in large-scale or complex applications.
  • •Strong understanding of Web application security (OWASP Top 10 and beyond), Authentication & authorization flaws, API security, and Injection attacks.
  • •Hands-on experience with manual security testing (not relying solely on automated tools).
  • •Ability to translate complex security findings into clear, actionable guidance for engineers.
Experience:5+ yearsSecurityApplication securityCybersecurity
Skills:CommunicationCollaborationMentoringProblem-solving
Languages:English
Tech Stack:OWASPThreat modelingSecurity-by-defaultSecurity testing

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor