Product Security Engineer | Vulnerability Response & Application Security

Own Company
Own Company

Product

Hyderabad, Telangana, India

Posted on Jun 19, 2026

Description

The security team at Salesforce works on some of the most challenging problems in information security. We are seeking a Product Vulnerability Engineer to join one of the world's leading vulnerability response teams. The pace and variety of our work create a unique learning environment, whether you are starting out or have deep security experience. You will be given unique challenges, the tools to solve them, surrounded by exceptional colleagues, and supported by incredibly helpful partner teams.

Product Vulnerability Engineers are responsible for:

  • Leading the response to lower/moderate severity vulnerabilities.

  • Participating in the response to high-severity vulnerabilities.

  • Managing and triaging security vulnerabilities, differentiating urgent issues from important ones.

  • Assessing complex problems, formulating action plans, and driving resolution under pressure.

  • Investigating and analyzing vulnerabilities to determine potential impact.

Successful vulnerability engineers thrive on challenges, remain calm under pressure, and can think on their feet.

Required Skills

  • 3-7 years of experience in information security or closely related roles, with direct experience in security vulnerability response

  • Experience managing common types of security vulnerabilities, such as OWASP Top 10.

  • Familiarity with common security threats and issues, including credential phishing, internal data spillage events, and inadvertent data leaks.

  • Application forensics skills, including collecting and analyzing code artifacts to assess potential impact if vulnerabilities are exploited.

  • Strong verbal and written communication skills, with the ability to clearly communicate complex scenarios to non-technical stakeholders.

  • Strong technical fundamentals, including:

    Networking fundamentals.

    Common application protocols.

    System architecture.

    Basics of software development.

  • Strong knowledge of web proxy tools and techniques.

  • Ability to research and quickly learn unfamiliar technologies while adapting existing knowledge and processes to investigate and resolve security issues.

  • Broad information security knowledge, including familiarity with key regulations and standards related to security vulnerability response.

Desired Skills

  • Prior experience utilizing AI tools for automation and analysis.

  • Experience working in a large and complex organization operating across multiple locations with a high degree of change.

  • Experience reproducing proof-of-concept exploitation steps.

  • Experience assessing vulnerability priority based on risk and impact.

  • Experience securing applications and infrastructure in Amazon Web Services and similar IaaS/PaaS platforms.

  • Deep application security knowledge, with the ability to map application vulnerabilities to exploitation indicators and relevant investigation techniques.

  • Relevant incident response or information security certifications, such as:

    • GIAC GWAPT

    • GIAC GCIH

    • GIAC GPEN

    • GIAC GXPN

    • Offensive Security OSCP