Principal Offensive Security – Red Team
Posted 45ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Offensive Security Principal executing complex red team operations at Salesforce. Leading adversary simulation across products and platforms to strengthen security posture.
Responsibilities:
- Design and personally execute complex, high-impact red team operations spanning the entire attack kill chain—from initial access through objective completion
- Simulate real-world threat actors by applying their tactics, techniques, and operational constraints to identify, exploit, and chain vulnerabilities across applications, identity systems, cloud environments, and enterprise infrastructure
- Develop and refine advanced offensive tradecraft, including novel exploitation techniques, custom tooling and payloads, and sophisticated bypasses of security controls and detections
- Analyze Salesforce products and platforms through an adversary's lens, understanding how threat actors might abuse, exploit, and chain vulnerabilities to achieve their objectives
- Act as the technical escalation point for complex exploitation paths, advanced attack chain validation, and challenging findings that require deep expertise to resolve
- Partner closely with the Red Team Director on campaign design and prioritization, collaborate with Detection & Response teams to stress-test visibility and response capabilities, and work alongside engineering and platform teams to explain root causes and drive durable security fixes
- Translate sophisticated attack scenarios into clear, technically rigorous remediation guidance that enables teams across the organization to understand not just what vulnerabilities exist, but why defenses failed and which changes will meaningfully disrupt real threat actors
- Mentor engineers and security professionals, raising the technical bar across the organization and evolving red team methodologies to stay ahead of emerging threats
Requirements:
- Degree or equivalent relevant experience required
- Deep, proven expertise in offensive security, including red teaming, high-impact penetration testing, or adversary simulation, with a strong attacker mindset
- Extensive hands-on experience executing realistic, end-to-end adversary attack campaigns
- Strong understanding of threat actor tactics, techniques, and procedures (TTPs) and attacker objectives and decision-making across the kill chain
- Strong understanding of identity, authorization, and trust abuse at scale
- Strong understanding of application security and attack paths
- Strong understanding of cloud and hybrid enterprise attack surfaces
- Hands-on experience with manual exploitation and advanced attack chaining
- Hands-on experience with custom tooling, exploitation, and/or payload development
- Hands-on experience bypassing layered security controls and detections
- Ability to clearly articulate how attackers achieved objectives, why defenses failed at each stage of the kill chain, and which changes will meaningfully disrupt real threat actors
- Strong communication skills and ability to influence across teams without formal authority
Benefits:
- wellbeing reimbursement
- generous parental leave
- adoption assistance
- fertility benefits


















