To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & Infrastructure
Job Details
Salesforce's platforms - including Core CRM and Marketing Cloud - let companies build, deliver, monitor, and scale their engagement with customers globally. Not everyone uses that access responsibly. We're looking for a Platform Trust and Safety Engineer who is dedicated to identifying and stopping abusers who commit fraud, phishing, and account takeover, or who otherwise use our services to make the internet a hostile space.
The Platform Defense and Safety (PDS) team detects and responds to malicious user activity - misuse, abuse, fraud, and crime - that occurs even when our systems are working as designed. At any given time, bad actors attempt to bypass detection and response systems by posing as legitimate customers to take unfair advantage of our services. Unlike account compromise, abuse tends to be a slow, simmering problem rather than a single event.
The Experience
- Extensive experience in information security roles involving platform abuse, threat intelligence, incident response, or threat detection
- Experience managing security or abuse investigations end to end: triage, evidence collection, risk assessment, containment, escalation, and closure
- Specialization in at least one of: log analysis, file-level forensics, or data mining
- Experience authoring detection rules using languages such as YARA or Splunk SPL, and comfort working from a command line
What You'll Actually Be Doing
- Review, triage, and respond to external and internal abuse reports across Core CRM and Marketing Cloud, with an eye toward expanding into new products
- Build and tune detection and response rules in Splunk, and author and maintain automated response playbooks
- Partner with our Office of Ethical Usage and Legal teams - including on regulatory reporting such as the EU Digital Services Act (DSA) - to keep our platforms free of malicious content
- Identify and document anti-abuse tooling requirements for engineering teams, and evaluate third-party vendor tools to close detection gaps
You're Our Person If...
- You track emerging trends in digital crime, merchant fraud, and abuse of AI/agentic capabilities
- You write and maintain clear playbooks, SOPs, and postmortems that drive continuous improvement
- You collaborate easily across teams - including Product Security Advisors, engineering, and product teams - and can contribute to platform abuse threat modeling
- You're comfortable participating in an on-call rotation
Even Better If...
- You can quickly and effectively understand someone else's code
- You have extensive experience using Splunk for detection engineering and SPL rule authoring
- You've worked with threat intelligence tools or teams
- You have experience with workflow orchestration or automation platforms (e.g., Temporal)
- You've worked in a customer-facing role (Support, Sales Engineering, etc.)
- You're familiar with evidence handling, privacy, data retention, and regulatory considerations relevant to security investigations
- You understand cloud/SaaS security concepts, multi-tenant platforms, identity systems, and application telemetry
- You have experience analyzing large, complex data sets, and familiarity with Git/GitHub and the Salesforce platform (Cases, SOQL)
Unleash Your Potential
When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future - but to redefine what's possible - for yourself, for AI, and the world.