Principal Threat Assessment Engineer at Salesforce addressing environmental threat assessments and mentoring junior analysts. Engaging with stakeholders to enhance security posture within global infrastructure.
Responsibilities
Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from a realized threat and “outside-in” perspective.
Utilizing threat intelligence, incident response data, detection and logging metrics, and visibility from proprietary security tooling to conduct and correlate research.
Assessing cloud security controls and cloud architecture implementations across current businesses and future M&As, primarily across AWS, GCP, and Azure substrates.
Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls.
Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products.
Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning.
Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing threat intelligence in the Salesforce context in partnership with our Threat Intelligence team.
Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats.
Requirements
12+ years of experience in threat modeling and security architecture, and/or other CSOC functions like Incident Response, Threat Detection, Threat Intelligence.
Significant understanding of threat actor tactics and offensive strategies.
Strong research and analytical skills with the ability to correlate data from various sources.
Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE.
In-depth knowledge of cloud security and cloud architecture fundamentals.
Proficiency in analyzing logs from various security tools.
Familiarity with application security, specifically with the OWASP Top 10 vulnerabilities.
Strong understanding of common exploitation and abuse threats observed across for SaaS and PaaS providers.
Excellent communication skills, both written and oral.
A related technical degree required.
Benefits
time off programs
medical
dental
vision
mental health support
paid parental leave
life and disability insurance
401(k)
employee stock purchasing program
Job title
Information Security Principal, Environment Threat Assessment
Lead Performance Engineer seeking to drive performance excellence across IAM applications for RBC. Own the complete performance testing lifecycle ensuring systems meet performance standards
Security Compliance Operation Manager at a mobility AI company focusing on software - defined vehicle development. Responsible for policy establishment, compliance support, and system security management.
Information Security Consultant helping SEB mitigate cybersecurity threats in the Baltic IT environment. Protecting customers' interests while maintaining a high level of service in a collaborative team.
Senior Engineer for Cybersecurity Incident Management Team at GEICO. Coordinate incident responses, perform forensic investigations, and collaborate across teams for enhanced security measures.
Information Security Consultant responsible for safeguarding SEB bank's cybersecurity across the Baltics. Collaborating within a skilled international team to protect customer interests.
Information Security Consultant focusing on cybersecurity for SEB bank. Protecting interests of corporate and private customers in the Baltic environment.
Endpoint User Security Solutionist designing and validating secure system infrastructures and security solutions for enterprise environments at HPE. Supporting cybersecurity improvements, testing, and architectural deployment.
Security Engineer managing cybersecurity services for local and multinational clients in Australia. Ensuring security compliance and assisting in high - priority incident responses.
Senior Full Stack Developer specializing in GenAI/ML at Hitachi Energy. Focused on building AI - driven solutions for real‑world cybersecurity challenges.
Senior Security Engineer developing security strategies for QuantumScape's lithium - metal battery technology. Leading incident response and orchestrating threat intelligence initiatives in a high - tech environment.