We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Director - Red Team Product Security

salesforce.com, inc.
parental leave, 401(k)
United States, Washington, Bellevue
Feb 26, 2026

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Product

Job Details

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Role Overview

We are looking for an experienced cyber security expert who will serve as Red Team Director with a deep hands-on offensive security mindset to lead and execute real-world adversary simulations across our products, platforms, and enterprise environment.

This role goes beyond Red Team exercises or reporting findings, you will actively uncover weaknesses in our products and features and use them as pivotal entry points to demonstrate how attackers can move from product abuse to broader platform, customer, or enterprise compromise, driving measurable improvements in security controls and Detection & Response capabilities.

You will lead and participate in red team operations, work as a trusted partner to engineering and Detection & Response teams to measurably raise the organization's security resilience against real attack scenarios.

Key Responsibilities

  • Lead and Execute hands-on Red Team operations simulating real-world threat actors across applications, platforms, cloud infrastructure, and enterprise environments.

  • Deeply understand our products through the lens of adversary abuse and exploitation

  • Design and conduct attack campaigns, emulating various attack scenarios.

  • Focus on high-impact weaknesses and chained vulnerabilities to achieve goals.

  • Actively perform offensive activities, including:

    • Engage with the AI-Automation team to develop sophisticated tools and frameworks.

    • Manual exploitation and chaining of weaknesses.

    • Abuse of identity, authorization, and trust relationships.

  • Drive Adversary-Centric thinking by:

    • Simulating realistic attacker objectives towards Salesforce and constraints

    • Prioritizing paths that lead to meaningful business impact

  • Partner with:

    • Detection & Response teams to test and improve visibility, alerts, and response metrics

    • Incident Response teams to evaluate containment and recovery effectiveness

    • Engineering and platform teams to explain exploitation paths and root causes

  • Reporting that will reflect a clear, actionable remediation guidance that improves security at scale.

  • Influence security strategy by:

    • Identifying recurring attack paths and systemic gaps

    • Recommending architectural, platform, and process-level improvements

  • Upskill Red Team operators and offensive security engineers, raising operational maturity and tradecraft quality.

Required Qualifications

  • Deep expertise in Offensive Security, Red Teaming/High Impact Pentesting, with a strong attacker mindset.

  • Proven personal experience executing Red Team/High Impact Pentesting engagements.

  • Strong understanding of:

    • Adversary tactics, techniques, and procedures (TTPs)

    • Identity and access abuse

    • Application/infrastructure attack kill chains

    • Cloud and hybrid enterprise attack surfaces

  • Hands-on experience with:

    • Manual/Automatic exploitation and attack chaining

    • Writing custom tooling, scripting, or payload development

    • Bypassing security controls and detections

  • Ability to clearly articulate:

    • How attacks work

    • Why defenses failed

    • What changes will meaningfully reduce risk

  • Communication skills and experience collaborating with security and engineering teams

Preferred Qualifications (Advantage)

  • Experience running Red Team Operations, Cyber-Research, and/or High impact Pentesting.

  • Research & Disclosure and Track record of discovering and responsibly disclosing security vulnerabilities through CVEs, Publications, Blogs or event Talks/Presentations

  • Malware analysis experience with practical real-world threat actor knowledge

  • Background in threat simulation, adversary emulation, or breach-and-attack methodologies.

  • Experience improving Detection & Response through Red/Purple team collaboration.

  • Familiarity with cloud architectures, identity, security models, and large systems.

Unleash Your Potential

When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future - but to redefine what's possible - for yourself, for AI, and the world.

Accommodations

If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that's inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $218,400 - $365,200 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $263,200 - $401,400 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.
Applied = 0

(web-54bd5f4dd9-lsfmg)