SENIOR PRODUCT SECURITY ENGINEER ENTERPRISE SECURITY
Job Field: Legal Jobs
Location: San Francisco, CA
Salary: $Not stated
JOB SUMMARY:
</tr>
<tr><td valign="top" width="450"><b>Responsibilities
Salesforce.com has one of the best Information
Security teams in the world and growing this piece
of the business is a top priority! Our Information
Security teams work hand in hand with the business
to ensure the highest security around all of our
applications. We are looking for an Senior or
Principal Product Security Engineer to provide
security support for salesforce.coms cloud
computing service. Youll work closely with the
technology organization to educate our team on
secure application development and help in
creating innovative security solutions for our
product. Additionally, you will play a key role
providing both strategic and tactical security
advice and help in developing technology solutions
which promote securing our customers data and
users.
Responsibilities
Identify and understand the development practices,
networks and infrastructure that make
salesforce.com successful
Guide the Information Technology organizations
security by participating in design reviews,
Threat Modeling, and in depth security penetration
testing of internally developed applications,
external services and third party products,
systems and services.
Provide input on application design, secure coding
practices, and application security.
Work with internal teams, third parties to
identify technology risk, prioritize, and work
with stakeholders to build solutions and
mitigation plans to help resolve technology risks.
Perform cutting edge research on new attacks,
write white papers and present on those findings
to internal audiences.
Required Skills
BS degree 4 year program
Minimum of 5 years working in application
development
Minimum of 2 years performing application security
assessments
The ideal candidate will have in-depth experience
protecting against web and web services security
vulnerabilities including cross-site scripting,
SQL injection, DoS attacks, XML/SOAP, API attacks,
Mobile platforms, email security flaws and more.
KEY REQUIREMENTS:
None Bachelors degree