onsite
Product Security Engineer Vulnerability Response & Application Security - Salesforce
Security Engineer
Product Security Engineer focused on vulnerability response and application security, leveraging Python, Java, SAST/DAST tools, and cloud security expertise within CI/CD pipelines to protect enterprise SaaS products.
About the role
Key Responsibilities
- Lead the detection, triage, and remediation of security vulnerabilities across web and mobile applications.
- Develop and integrate automated security testing (SAST, DAST) into CI/CD pipelines to ensure continuous protection.
- Collaborate with development, product, and operations teams to embed security best practices throughout the software development lifecycle.
- Perform root‑cause analysis of security incidents and provide actionable guidance to engineering teams.
- Maintain and improve cloud security posture on platforms such as AWS, including configuration reviews and threat modeling.
Requirements
- 3+ years of hands‑on experience in application security or vulnerability management.
- Proficiency in programming/scripting languages such as Python and Java.
- Strong knowledge of security testing tools (e.g., SAST, DAST, static code analysis, penetration testing frameworks).
- Experience integrating security controls into CI/CD workflows and cloud environments (AWS preferred).
- Excellent problem‑solving and communication skills, with the ability to influence cross‑functional teams.