Product Vulnerability Engineer

Salesforce

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Mclean, VA
Salary
$117,200–$176,700 / yr
Posted
9 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $147k
$105k most similar roles pay here $232k

This role pays less than 78% of similar roles. Most pay $154,469–$208,800 — the shaded band above. At the midpoint, this role pays about $147k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 106 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 98 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Product Vulnerability Engineer

The Product Vulnerability Engineer joins a leading vulnerability response team to manage and triage multiple security vulnerabilities while leading responses to lower and moderate severity issues and participating in high-severity cases. The role involves assessing complex problems, formulating action plans under pressure, and performing application forensics by analyzing code artifacts to determine potential impact from exploits. Key responsibilities include investigating common threats like credential phishing and data leaks while communicating technical scenarios to non-technical colleagues. Required skills include networking fundamentals, system architecture, software development basics, and web proxy tools. The candidate must possess experience with the OWASP Top 10, infrastructure security in Amazon Web Services, and reproducing proof of concept exploitation steps. This role addresses critical information security challenges by identifying, prioritizing, and resolving vulnerabilities within a complex technical environment to ensure robust product security.

What you'll do

  • Lead the response efforts for low and moderate severity security vulnerabilities.
  • Participate in the coordinated response to high-severity security vulnerabilities.
  • Triage multiple security vulnerabilities simultaneously while prioritizing urgent issues over less critical ones.
  • Perform application forensics by collecting and analyzing code artifacts to assess potential exploit impacts.
  • Formulate action plans and resolve complex security problems under high-pressure situations.
  • Communicate complex technical scenarios clearly to non-technical colleagues and stakeholders.
  • Research and learn unfamiliar technologies quickly to investigate and resolve emerging security issues.

What we're looking for

  • Must be a U.S. citizen (born or naturalized) who does not hold dual citizenship.
  • Must be able to pass a U.S. federal government Minimum Background Investigation for a Moderate Public Trust position.
  • 5-7 years of experience in information security or closely related roles with direct experience in security vulnerability response.
  • Experience managing common types of security vulnerabilities, such as the OWASP Top 10.
  • Application forensics skills to collect and analyze code artifacts to assess potential impact from exploitation.
  • Strong knowledge of networking fundamentals, system architecture, web proxy tools, and software development basics.
  • Ability to communicate complex technical scenarios clearly to non-technical colleagues.
  • Relevant certifications such as GIAC GWAPT, GCIH, GPEN, GXPN, or Offensive Security OSCP are preferred.

More like this

Similar roles

Vulnerability Management Engineer

SoFi

San Francisco, CA 7 days ago $99,200$186,000
Vulnerability Management AppSec SAST DAST AWS Python Go Bash Java CI/CD OWASP CVE CVSS Agile

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 53 days ago $125,000$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Senior Product Security Engineer

Adobe

San Jose, CA 7 days ago $180,600$261,450
OWASP Top 10 CVSS v3.1 Burp Suite Python PowerBI JIRA REST API OAuth2 AWS Lambda API Gateway SQL Injection XSS SSRF IDOR SOAR Webhooks curl DevTools
5+ yrs exp

Lead Vulnerability Commander

Salesforce

Remote (VA) 32 days ago $172,500$260,100
Vulnerability Management Incident Response Security Operations AWS GCP Azure Windows Mac Linux Forensics SLA Tracking Automation cyber security
8+ yrs exp Remote

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 10 days ago $117,200$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote