Job Summary
We are seeking an experienced Salesforce Security Engineer to support the security operations, vulnerability management, incident response, and security governance of a Salesforce Service Cloud environment. The role will proactively identify and address security vulnerabilities, coordinate security remediation and patching activities, support penetration testing, and collaborate closely with internal security teams and external security vendors. The ideal candidate will have strong experience in application security, vulnerability management, incident response, security assessments, and enterprise Salesforce environments, with the ability to independently manage security issues and provide practical remediation guidance.
Key Responsibilities
• Own and drive security incident response activities for the Salesforce Service Cloud platform.
• Triage, assess, and prioritize findings from internal security scans and vulnerability assessments.
• Analyze identified vulnerabilities and determine potential business, application, and security impacts.
• Develop and coordinate remediation plans for security vulnerabilities and identified risks.
• Plan and coordinate security patches, hotfixes, and other security-related remediation activities.
• Support penetration testing activities by coordinating with external security vendors and internal cybersecurity teams.
• Assist with security assessments of Salesforce Service Cloud and its custom application components.
• Provide security architecture guidance for Salesforce platform changes and enhancements.
• Review proposed platform changes to help ensure they maintain required security, compliance, and risk standards.
• Collaborate with internal security teams on vulnerability scanning, exploit assessment, remediation planning, and incident response.
• Maintain clear documentation of security incidents, vulnerabilities, remediation activities, and post-incident findings.
• Participate in post-incident reviews and identify opportunities to improve the Salesforce security posture.
• Work closely with Salesforce development, platform, and engineering teams to identify and address security risks.
• Proactively identify security and process gaps and recommend improvements.
• Support security governance activities and contribute to sustainable security practices for the Salesforce Service Cloud environment.
• Operate independently within an established Salesforce delivery team, escalating issues appropriately while driving security outcomes without requiring continuous direction.
Required Qualifications
• Proven experience in application security, vulnerability management, incident response, and security assessments.
• Experience supporting security operations within enterprise application environments.
• Experience identifying, triaging, and prioritizing security vulnerabilities from security scans or assessments.
• Experience developing and coordinating vulnerability remediation and security patching activities.
• Experience supporting penetration testing engagements and working with external security vendors.
• Strong understanding of application security principles, vulnerability management, and security risk assessment.
• Experience collaborating with internal cybersecurity, engineering, application development, and platform teams.
• Strong analytical and troubleshooting skills with the ability to assess security issues and determine appropriate remediation approaches.
• Excellent written and verbal communication skills, including the ability to document security incidents and communicate risks and recommendations to technical and non-technical stakeholders.
• Ability to independently manage multiple security initiatives and priorities in a complex enterprise environment.
Preferred Qualifications
• Experience with Salesforce Service Cloud security and enterprise Salesforce environments.
• Experience securing custom Salesforce applications and integrations.
• Familiarity with Salesforce security architecture, access controls, data protection, and platform security best practices.
• Experience working with highly regulated or enterprise-scale environments.
• Experience coordinating with external penetration testing and security assessment vendors.
• Experience participating in security architecture reviews and post-incident analysis.
• Experience working within Agile delivery teams and established enterprise security governance processes.
Certifications
• Security certifications such as CISSP, CISM, CEH, OSCP, or equivalent are preferred but not explicitly required.
Primary Skills
• Application Security
• Vulnerability Management
• Incident Response
• Security Assessments
• Penetration Testing Coordination
• Security Architecture
• Vulnerability Triage and Remediation
• Salesforce Service Cloud Security