Enterprise Application Engineer (Enterprise Security - Security AI)
Software Engineering, Data Science
San Francisco, CA, USA · Texas, USA · Austin, TX, USA · McLean, VA, USA · Bellevue, WA, USA · New York, NY, USA · Seattle, WA, USA · Dallas, TX, USA
Note: Your are applying to an Enterprise Application Engineer posting. Geo locations and levels may vary.
The Experience
Salesforce Enterprise Security is hiring a Enterprise Application Security Engineer, for our Secure AI team. In this role, you will partner with business stakeholders and technology partners to assess and maintain the security of AI tooling, ensuring they meet or exceed Salesforce security requirements when deploying AI at scale. You will have the opportunity to identify emerging threats, design new processes that balance security and business agility, and share your knowledge through internal events, conferences, and research.
What You'll Actually Be Doing
- Conduct in-depth security assessments of emerging AI technologies — including architecture and design reviews, code reviews, and penetration tests — while providing guidance on remediation and feature enhancements
- Threat model common attacker methods to develop mitigation techniques that balance security requirements with functional needs
- Collaborate with engineering teams and business partners to drive solutions through a secure development lifecycle, and define technical security standards and guidelines
- Research new technologies, emerging threats, and vulnerabilities to support strategic planning and process improvements
- Build tools to enable secure use of AI at scale
You're Our Person If...
- 5+ years of experience in a security engineering role including Application Security and Pen testing experience (Senior/SMTS)
- 8+ years of experience in a security engineering role including Application Security and Pen testing experience (Lead/LMTS)
- Develop automated processes and support improvement of tooling to identify and solve problems at scale
- Experience with large language models (LLMs) and agentic systems — building, evaluating, or securing them
- Experience with AI security attack surfaces including prompt injection, data exfiltration, privilege escalation in agents, and model supply chain risks
- Understanding of RAG architectures, classifier models, and how retrieval and generation pipelines work
- Excellent interpersonal, collaboration, and critical-thinking skills
- A related technical degree required
Even Better If...
- Familiarity with standard security frameworks such as ISO 27001, SOC 2, PCI DSS, OWASP Top 10, CWE Top 25, and MITRE ATT&CK
- Relevant BA/BS degree and/or certifications such as CRISC, CISSP, CCIE, CISM, CISA, or CCSK
- Experience defining and communicating security remediation tasks to project and data owners