Principal Threat Assessment Engineer at Salesforce addressing environmental threat assessments and mentoring junior analysts. Engaging with stakeholders to enhance security posture within global infrastructure.
Responsibilities
Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from a realized threat and “outside-in” perspective.
Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.
Assessing cloud security controls and cloud architecture implementations across current businesses and future M&As, primarily across AWS, GCP, and Azure substrates.
Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.
Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.
Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning.
Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing threat intelligence in the Salesforce context in partnership with our Threat Intelligence team.
Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats.
Requirements
12+ years of experience in threat modeling and security architecture, and/or other CSOC functions like Incident Response, Threat Detection, Threat Intelligence.
Significant understanding of threat actor tactics and offensive strategies.
Strong research and analytical skills with the ability to correlate data from various sources.
Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.
In-depth knowledge of cloud security and cloud architecture fundamentals.
Proficiency in analyzing logs from various security tools.
Familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.
Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
Excellent communication skills, both written and oral.
A related technical degree required.
Benefits
time off programs
medical
dental
vision
mental health support
paid parental leave
life and disability insurance
401(k)
employee stock purchasing program
Job title
Information Security Principal, Environment Threat Assessment
Head of Information Security at Aurora shaping security strategy and governance in a software - focused global business. Leading security efforts to ensure resilience and compliance across operations.
Senior Security Engineer specializing in penetration testing and security strategies for fintech. Collaborating with teams to enhance security for AI applications and financial systems.
Principal Cyber Security Engineer for Identity Access Management at MSK managing identity solutions and advanced identity platforms. Partnering with stakeholders to align identity strategy and lead IAM initiatives.
Join The Missing Link as a Security Engineer, leveraging 3 - 4 years of IT Security experience. Lead projects in a collaborative environment with a focus on innovation and impact.
Engineer in Health, Safety and Environment for ArianeGroup focusing on industrial risk management. Involves audits, assessments, and safety training participation.
Senior Product Security Engineer at Red Hat focusing on security and compliance for digital sovereign products while collaborating across global teams and enhancing automation.
Security Engineer safeguarding K - 12 student data in several locations for EduTech startup. Designing secure software systems and ensuring data protection to comply with privacy standards.
Security Engineer focusing on data protection and privacy for Kira Learning's educational technology. Safeguarding K - 12 student data while collaborating with engineering teams on secure software development.
Senior Cybersecurity Engineer responsible for protecting Advansys and its clients' IT infrastructure. Designing, implementing, and managing security solutions, while mentoring junior engineers.
Security Engineer responsible for incident response and security protocol design at Sinch. Joining a global team to safeguard sensitive information and enhance cybersecurity measures.