Level

Salesforce

Penetration Testing Engineer, MTS

AI in this role

Execute hands-on penetration testing across applications, cloud infrastructure, and AI systems including prompt injection and LLM security.

kubernetesdocker
ai-agentspenetration-testingapplication-securityoffensive-securityprompt-injectionvulnerability-assessment

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Product

Job Details

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Penetration Testing Engineer, MTS

The Experience

We are looking for a Penetration Testing Engineer to execute deep, hands-on penetration tests across our applications, platforms, cloud infrastructure, and AI-powered systems. You'll bring a hacker mindset to real exploitation and attack chaining rather than checklist-driven testing, working under the guidance of senior team members on complex engagements.
You'll partner with engineering and AppSec teams to turn findings into concrete remediation, while building your skills across cloud, identity, and AI/ML attack surfaces.

What You'll Actually Be Doing

  • Execute penetration tests across web applications, APIs, cloud/hybrid infrastructure (Kubernetes, Docker), identity and trust boundaries, and AI/ML-enabled systems, including prompt injection and abuse of AI integrations.
  • Perform manual exploitation beyond automated tooling, including business logic abuse, privilege escalation, and identity/access trust relationship abuse.
  • Support engagements through scoping, execution, risk assessment, and clear reporting with remediation guidance.
  • Produce technically detailed reports covering exploitation paths, missing security controls, and mitigation recommendations, and collaborate with engineering, AppSec, and Detection & Response teams on findings.

You're Our Person If...

  • You have 2-4 years of hands-on experience in penetration testing, offensive security, or application security testing.
  • You have experience performing penetration testing engagements in production or production-like environments, using manual techniques and automation/AI tools.
  • You understand application security vulnerabilities and attack chains, identity and access control failures, cloud security fundamentals, and security risks specific to AI and LLM-based systems.
  • You can clearly articulate exploitation mechanics, impact, and practical remediation steps to engineers and security teams.

Even Better If...

  • You have experience with custom scripts, payloads, or proof-of-concept development.
  • You've participated in Bug Bounty programs.
  • You're familiar with cloud architectures and identity-centric security models.
  • You have experience using AI/LLMs for offensive security work or vulnerability discovery.

Unleash Your Potential

When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.

The typical base salary range for this position is $117,200 - $176,700 annually. 

The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

How we rate this

Penetration Testing Engineer, MTS at Salesforce rates 65 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.

Classification

Works on AI. The daily work is on AI products, without building the model.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

AI AgentsPenetration TestingApplication SecurityOffensive SecurityPrompt InjectionVulnerability AssessmentKubernetesDocker

Questions you could be asked

  1. How do you decide when an AI agent can act on its own versus asking for approval first?
  2. Tell me about a project where penetration testing was part of your work. What did you do?
  3. Tell me about a project where application security was part of your work. What did you do?
  4. Tell me about a project where offensive security was part of your work. What did you do?
  5. Tell me about a project where prompt injection was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: AI Agents, Penetration Testing, Application Security, Offensive Security, and Prompt Injection. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new remote cybersecurity jobs (Works on AI ●●●○ or higher) by email

One email a week with the new remote cybersecurity jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Software Engineering roles that work on AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Salesforce

More cybersecurity jobs

Related searches

Same AI level