Senior Threat Assessment Engineer

Own Company

Own Company

San Francisco, CA, USA

Posted on May 2, 2026

Description

Overview of the Role:

As a Senior Threat Assessment Engineer on the Environmental Threat Assessment team, you will utilize the threat (and detection/response) perspective to lead independent assessments into new M&As, major product releases, incident uplifts, etc to identify and mitigate exploitable vectors. You will collaborate with peers across intelligence, detection, and response functions to drive uplifts and scale our capabilities through automation and "agentic" security investments. Your work will directly shape Salesforce’s security posture by translating technical research into actionable requirements for Product & Enterprise Security partners and Product/Engineering stakeholders.

Responsibilities:

  • Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture and interactions, and new products/features from a realized threat and “outside-in” perspective.

  • Create onboarding strategy of all new M&As into Cyber Security Operations across assessments, log prioritization and onboarding, and detection and security tool validation.

  • Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.

  • Assessing cloud security controls and cloud architecture implementations across current businesses and future business units, primarily across AWS, GCP, and Azure substrates.

  • Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.

  • Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.

  • Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing intelligence in the Salesforce context with our Threat Intelligence team.

Required Qualifications:

  • 6+ years of experience in threat modeling and security architecture.

  • Strong research and analytical skills with the ability to correlate data from various sources.

  • Proficiency in analyzing logs and events from various security tools like EDR, CSPM, SIEM, etc.

  • In-depth understanding of cloud security and application security fundamentals and best practices (such as OWASP Top 10).

  • Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.

  • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.

  • Excellent communication skills, both written and oral.

  • A related technical degree required.

Preferred Qualifications:

  • Experience in Product or Enterprise Security design reviews and security assurance.

  • Experience automating processes and/or using AI tooling to automate workflows and data analysis.

For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.