Penetration Testing Engineer, MTS

Salesforce•Herndon, CA

About The Position

Salesforce is looking for a Penetration Testing Engineer to execute deep, hands-on penetration tests across their applications, platforms, cloud infrastructure, and AI-powered systems. The role involves bringing a hacker mindset to real exploitation and attack chaining rather than checklist-driven testing, working under the guidance of senior team members on complex engagements. The engineer will partner with engineering and AppSec teams to turn findings into concrete remediation, while building skills across cloud, identity, and AI/ML attack surfaces.

Requirements

  • 2-4 years of hands-on experience in penetration testing, offensive security, or application security testing.
  • Experience performing penetration testing engagements in production or production-like environments, using manual techniques and automation/AI tools.
  • Understanding of application security vulnerabilities and attack chains, identity and access control failures, cloud security fundamentals, and security risks specific to AI and LLM-based systems.
  • Ability to clearly articulate exploitation mechanics, impact, and practical remediation steps to engineers and security teams.

Nice To Haves

  • Experience with custom scripts, payloads, or proof-of-concept development.
  • Participation in Bug Bounty programs.
  • Familiarity with cloud architectures and identity-centric security models.
  • Experience using AI/LLMs for offensive security work or vulnerability discovery.

Responsibilities

  • Execute penetration tests across web applications, APIs, cloud/hybrid infrastructure (Kubernetes, Docker), identity and trust boundaries, and AI/ML-enabled systems, including prompt injection and abuse of AI integrations.
  • Perform manual exploitation beyond automated tooling, including business logic abuse, privilege escalation, and identity/access trust relationship abuse.
  • Support engagements through scoping, execution, risk assessment, and clear reporting with remediation guidance.
  • Produce technically detailed reports covering exploitation paths, missing security controls, and mitigation recommendations, and collaborate with engineering, AppSec, and Detection & Response teams on findings.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service