Skip to content
← Back to job listings

Mobile Security Engineer (Product Security)

Salesforce · San Francisco, United States

External listingfull-timeabout 1 month ago

About The Role

Join Salesforce's Product Security team as a Mobile Security Engineer. You will be responsible for the security posture of Salesforce's mobile application portfolio, conducting security assessments, managing mobile scanning platforms, and providing security guidance to engineering teams. You will also build and ship high-quality security tooling and automation, integrating AI into security workflows.

  • Assumer la responsabilité de la posture de sécurité du portefeuille d'applications mobiles de Salesforce, y compris les tests de sécurité des applications mobiles et les revues de conception de sécurité.
  • Effectuer des évaluations de sécurité manuelles et automatisées des applications iOS et Android, y compris l'ingénierie inverse binaire, l'instrumentation dynamique et l'examen des flux OAuth/PKCE.
  • Fournir des conseils en matière de sécurité mobile aux équipes d'ingénierie, traduire les résultats en actions correctives et servir d'expert en sécurité mobile pour la planification des versions.
  • You have strong communication skills with the ability to explain mobile-specific risks to engineering partners who may not have mobile security context
  • You bring a demonstrated, genuine AI-first approach to engineering — using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty
  • A related technical degree required
  • You have advanced prompt engineering skills and the ability to write precise, structured prompts and cultivate the system context that makes AI outputs reliable, secure, and production-ready
  • You have experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor, etc.) in development workflows
  • You have 2+ years in application security, mobile security testing, or mobile development with demonstrated knowledge of iOS and Android platform security models, the Open Web Application Security Project (OWASP) Mobile Top 10, and common mobile vulnerability classes
  • Familiarity with security testing tools such as Frida, NowSecure, objection, MobSF, Burp Suite, or commercial mobile Static/Dynamic Application Security Testing (SAST/DAST) platforms
  • You have hands-on experience with the mobile platform toolchain (Xcode/Android Studio)
  • You have an understanding of mobile authentication patterns (OAuth 2.0, PKCE, SAML), runtime protection mechanisms (code obfuscation, anti-hooking, anti-tampering), and app store ecosystem security considerations for both Apple and Google Play
  • You have experience evaluating mobile runtime protection tools such as Promon, DexGuard, or similar Runtime Application Self-Protection (RASP) solutions on jailbroken or rooted devices
  • You hold mobile-focused security certifications such as GIAC Mobile Device Security Analyst (GMOB), or general offensive certifications such as Offensive Security Certified Professional (OSCP) or Offensive Security Web Expert (OSWE) with demonstrated mobile testing experience
  • You have active participation in mobile bug bounty programs (HackerOne, Bugcrowd), published mobile security research, Common Vulnerabilities and Exposures (CVE) disclosures, or contributions to open-source mobile security tools
  • You have experience with mobile CI/CD pipelines, automated binary scanning integration, or familiarity with the Salesforce ecosystem and applying AI tools such as Claude, Cursor, or Gemini for security assessments

This is an external listing. JobSpring does not represent or verify the employer. Report this listing