
Lead Threat Assessment Engineer
CAJobPosted 1 day agoStill listed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Lead Threat Assessment Engineer serves as an assessment lead and subject matter expert on Salesforce’s Environmental Threat Assessment team. The role conducts complex threat assessments, mentors junior analysts and engineers, and helps scale capabilities through automation and agentic security investments. It translates technical research into actionable requirements for Product and Enterprise Security partners and Product and Engineering stakeholders within the Cybersecurity Operations Center.
Skills & qualifications
Skills
Qualifications
Benefits
Full job description
Description The Experience As a Lead Threat Assessment Engineer on the Environmental Threat Assessment team, you serve as an assessment lead and subject matter expert, supporting and building how we identify and mitigate threats across our global infrastructure. You will not only execute complex threat assessments but also mentor a team of junior analysts and engineers, helping to scale our capabilities through automation and "agentic" security investments. Your work will directly shape Salesforce’s security posture by translating deep technical research into actionable requirements for Product & Enterprise Security partners and Product/Engineering stakeholders. This role is within the Cybersecurity Operations Center vertical of Salesforce Security.
What You'll Actually Be Doing:
- Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from an observed/realized threat and outside-in perspective.
- Utilizing threat intelligence, incident response and detection telemetry, proprietary security tooling, and internal security and risk signals to correlate research and manage Salesforce’s top threats program.
- Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls, across new and existing business units.
- Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.
- Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning.
- Design and orchestrate new agentic tooling for the team analysis capabilities and projects, supported by frontier harnesses, org-specific skills, and human workflows.
- Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing intelligence in Salesforce context in partnership with Threat Intelligence.
- Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats.
You're Our Person If You Have:
- 8+ years of experience in threat modeling and security architecture.
- Significant understanding of threat actor tactics and offensive strategies and strong research and analytical skills with the ability to correlate data from various sources.
- Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE, and familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.
- In-depth knowledge of cloud security and cloud architecture fundamentals and strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
- Proficiency in analyzing logs from various security tools.
- Excellent communication skills, both written and oral.
- A related technical degree required.
Even Better If You Have:
- Experience in Product or Enterprise Security design reviews and security assurance.
- Experience automating processes and/or using AI tooling to automate workflows and data analysis.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Lead Threat Assessment EngineerSalesforce · San Francisco, CA · $173–260K/yrPosted 3 days agoPosted 3 days ago
Product Security EngineerSalesforce · Bellevue, WA · $117–177K/yrPosted 1w agoPosted 1w ago
Product Security Engineer, SeniorSalesforce · Bellevue, WA · $149–224K/yrPosted 1w agoPosted 1w ago
Staff Threat ResearcherZscaler · Remote · US · $123–175K/yrPosted 1w agoPosted 1w ago
Manager, MDR & Threat HuntingZscaler · Remote · US · $144–205K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.