Jobs
>
San Francisco

    Senior Security Assurance Engineer - San Francisco, CA, United States - Salesforce

    Default job background
    Description

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category

    Product Job Details About Salesforce We're Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you've come to the right place. About Us Security Assurance works to ensure no significant security risk escapes into customer-facing products, the supporting infrastructure, or our enterprise technology stack by proactively scaling security practices at all stages of the engineering and development lifecycle. Security Assurance supports our engineering teams on the full stack; from the application layer down, ensuring the security of our customer-facing products, and being security domain guides to engineering teams across Salesforce. The Foundation & Acquisition & Security Focus Team is responsible for securing internal security and foundational services. This includes security controls and build infrastructure for all Salesforce products. As part of the Secure Software development lifecycle, we play a critical role in conducting design and implementation assessments, performing application and infrastructure security reviews, penetration testing, researching security issues, building security tools, and offensive security engagements. We aim to identify and reduce risk across Salesforce. Primary Responsibilities
    • Ability to secure large, sophisticated enterprise architectures or systems deployed in public cloud
    • Partner with engineering teams; performing threat modeling / data flow diagramming / architecture risk analysis, identifying security flaws, and driving work items and bugs from these activities to resolution
    • Brainstorm with counterparts in the product teams to drive security improvements upstream. Identify the trade-offs of different solutions and recommend the optimal design to achieve both functional goals and security requirements
    • Perform penetration testing, infrastructure/vulnerability assessments, and remediation activities. Work with engineering teams throughout the SDLC to ensure their efforts are secure
    • Develop new automation and tooling to improve our detection and prevention capabilities
    • Develop secure code practices and provide hands-on training to engineering and operations
    • Research new technologies, emerging threats, and vulnerabilities
    • Perform innovative applied research on new attacks and present new findings to both internal and external audiences.
    Minimum Qualifications
    • Bachelor's degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
    • 3 + years proven track record in the following areas in a security engineering or research role:
    • Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
    • Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS, XML/SOAP, API etc.
    • Public Cloud security architecture and testing in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud etc.
    • Experience with software development languages such as: JavaScript, Java, Python, Ruby, PHP, Go
    • Technical knowledge of security topics across infrastructure security & application security domains
    • Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
    • Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, and thoughtfully to partners from a variety of backgrounds, including those who are non-technical.
    Preferred Qualifications
    • An attacker's mindset; consider abuse and attack paths as well as the defensive approach to recommendations to prevent them
    • A passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.
    • Reasonable understanding of cryptography and able to recommend standard solutions for protecting data at rest and in storage, transport and identity purposes
    • Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns
    • Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle
    • Some experience performing penetration testing or familiarity with the process
    Accommodations If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form. Posting Statement At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at and explore our company benefits at Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce. Salesforce welcomes all. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. For Washington-based roles, the base salary hiring range for this position is $146,600 to $201,700. For California-based roles, the base salary hiring range for this position is $160,000 to $220,000. Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: #J-18808-Ljbffr


  • Ultradent West Valley City, United States

    Design Assurance Engineer. Ultradent, the global name in oral health is seeking a personable and passionate Design Assurance Engineer to contribute to the development of medical device, drug, and cosmetic products. You would be a member of a team of Assurance, Engineer, Design, C ...


  • Sigmaways Inc San Francisco, United States

    As an Automation Engineer, you will verify and validate whether products or services meet specified functional and non-functional requirements and quality targets. Implements quality assurance objectives and processes, monitors and evaluates testing results against the predetermi ...


  • Workflow86 San Francisco, CA, United States

    Full Time] Founding QA Engineer at Workflow86 (United States) | BEAMSTART Jobs Founding QA Engineer · Full Time · Remote Work · Stock Options · We're on a mission to translate the 99% of operation knowledge and expertise held by non-technical teams into massively scalable sof ...


  • SimplyInsured San Francisco, United States

    About SimplyInsuredSimplyInsured is on a mission to eliminate the fear from purchasing and navigating health insurance in the United States. We specifically work with small business owners who have the enormous task of purchasing the right type of insurance for their employees an ...


  • Volta Charging San Francisco, United States

    At Volta we're on a mission to accelerate the adoption of the electric vehicle. Volta's award-winning charging stations benefit brands, consumers, and real-estate locations by providing valuable advertising space to businesses and convenient charging to drivers. Strategically loc ...


  • MyShell San Francisco, United States

    About the Role · We are seeking a highly skilled and passionate · QA Lead · to join our team and ensure the quality and reliability of our products. This is a fully remote position open to candidates worldwide, with a strong preference for those based in the United States or C ...


  • Sigmaways San Francisco, United States

    As an Automation Engineer, you will verify and validate whether products or services meet specified functional and non-functional requirements and quality targets. Implements quality assurance objectives and processes, monitors and evaluates testing results against the predetermi ...


  • Motion Recruitment San Francisco, United States

    Job Description - QA Engineer: · • Work with product managers and developers and come up with a proper test plan, test scenarios, and estimates for test execution and production deployment. · • Execute test cases, report bugs, and monitor/track the entire bug life cycle. · • Eval ...


  • Solomon Page San Francisco, United States

    Our client, a well-known retail company, is looking for a QA Engineer with a background in mobile app development (iOS and Android) to join their team for a 10-month contract. Seeking a Mobile QA Engineer who is adept at finding bugs in software. As a QA Engineer, you will be res ...


  • Motion Recruitment San Francisco, United States

    Job Description - QA Engineer: · Want to make an application Make sure your CV is up to date, then read the following job specs carefully before applying. · • Work with product managers and developers and come up with a proper test plan, test scenarios, and estimates for test e ...


  • Lumicity San Francisco, United States

    QA Engineer - SF Bay Area · Are you the right applicant for this opportunity Find out by reading through the role overview below. · Well-funded, high growth connected device start-up in the Bay Area looking to hire a QA Engineer for their growing systems test team.Qualification ...


  • Motion Recruitment San Francisco, United States

    Job Description - QA Engineer: · • Work with product managers and developers and come up with a proper test plan, test scenarios, and estimates for test execution and production deployment. · • Execute test cases, report bugs, and monitor/track the entire bug life cycle. · • E ...


  • Lumicity San Francisco, United States

    QA Engineer - SF Bay Area · Well-funded, high growth connected device start-up in the Bay Area looking to hire a QA Engineer for their growing systems test team. · Qualifications · 6+ years of experience in QA / systems testingComfortable in a lab environment, proficient in ma ...


  • Stripe San Francisco, United States Full time

    Who we are About Stripe · Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our ...


  • LifeStance Health San Francisco, United States

    At LifeStance Health, we strive to help individuals, families, and communities with their mental health needs. Everywhere. Every day. It's a lofty goal; we know. But we make it happen with the best team in mental healthcare. · Thank you for taking the time to explore a career wi ...


  • Unlayer San Francisco, United States

    We are Unlayer, a software company on a mission to empower everyone to be creative. We are a global team of awesome people working from over 4 countries around the globe. We hire globally; you work locally - in the heart of San Francisco, a beach outside of So Paulo, or a quiet v ...


  • Sigmaways Inc San Francisco, United States

    As a Quality Assurance Engineer, you will be responsible for creating and implementing a strategy for quality coordination and testing as well as suggesting solutions to identified quality problems. You'll be essential to the quality and drive full automation of testing and quali ...


  • Unlayer San Francisco, United States

    We are Unlayer, a software company on a mission to empower everyone to be creative. We are a global team of awesome people working from over 4 countries around the globe. We hire globally; you work locally - in the heart of San Francisco, a beach outside of São Paulo, or a quiet ...


  • Sirona Medical San Francisco, United States

    At Sirona Medical we're building tools for physicians to work as fast as they can think. Many billions of patient images are acquired each year in the U.S., and nearly all of them are reviewed and diagnosed by a radiologist. In fact, 80% of healthcare data flows through radiology ...


  • Sirona Medical San Francisco, United States

    At Sirona Medical we're building tools for physicians to work as fast as they can think. · Many billions of patient images are acquired each year in the U.S., and nearly all of them are reviewed and diagnosed by a radiologist. In fact, 80% of healthcare data flows through radiol ...