Jobs · Engineering · California

Sr. Security Software Engineer, Vulnerability Management - Slack

Slack · San Francisco, CA · 2 wk ago
Engineering$173k–$260k/yrFull-time

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action, tech meets trust, and innovation is a way of life. The Vulnerability Management team at Slack plays a pivotal role in identifying, assessing, and mitigating security risks across our entire infrastructure, ensuring low-friction, high-impact security.

About the role

As a Senior Software Engineer on the Vulnerability Management team, you will build and maintain the systems and tooling used to detect, track, and remediate security vulnerabilities across Salesforce and Slack. You will drive technical strategy for automating and scaling vulnerability management, collaborate with security engineers, product teams, and infrastructure partners, and help raise the bar for how the team builds software. This is a high-impact, high-ownership role for someone who wants to do meaningful engineering work while shaping security at scale.

Responsibilities

  • Contribute to the technical architecture for vulnerability management tooling, including systems that automate identification, prioritization, tracking, and remediation of vulnerabilities across diverse ecosystems and environments.
  • Design and develop high-quality, scalable engineering solutions, balancing long-term maintainability with the practical needs of a fast-moving security organization.
  • Drive integration strategy across vulnerability scanners, aggregation pipelines, and downstream systems, making principled decisions about data ownership, tool consolidation, and signal quality.
  • Partner with cross-functional stakeholders including infrastructure, platform engineering, and product security teams to embed security automation deeper into the development lifecycle.
  • Identify systemic gaps and ambiguous, high-priority problems that cut across team boundaries, propose solutions, and drive them to completion with or without direct authority.

Requirements

  • U.S. Citizenship or Permanent Residency (Green Card holder). Visa sponsorship is not available for this role.
  • 6+ years of industry software engineering experience, with a meaningful portion in security engineering, platform engineering, or infrastructure-adjacent domains.
  • Deep proficiency in Python, with a strong track record of writing production-grade, tested, maintainable code in complex systems.
  • Demonstrated experience owning and delivering end-to-end engineering projects, from early-stage design through production deployment and ongoing operation.
  • Solid understanding of vulnerability management concepts, including how vulnerabilities are discovered, classified, prioritized, and remediated in enterprise environments.
  • Experience building or maintaining integrations with security tooling such as vulnerability scanners, SIEM systems, or similar platforms.
  • Comfort working with CI/CD pipelines, version control workflows, and modern software delivery practices.
  • Experience working across teams and communicating technical concepts clearly to both engineers and non-technical stakeholders.
  • Strong judgment in the face of ambiguity, and a track record of asking the right questions before building rather than after.

Nice-to-Have

  • Hands-on experience with vulnerability management tooling such as Wiz, Tenable/Nessus, Twistlock, or similar products, particularly in cloud or containerized environments.
  • Familiarity with compliance frameworks relevant to government or regulated environments, such as FedRAMP or DoD IL5/IL6.
  • Experience working with large-scale vulnerability aggregation systems or homegrown data pipelines that normalize findings across multiple scanners.
  • Background in building automated remediation workflows, such as automated PR generation for dependency vulnerabilities or patch orchestration across diverse package ecosystems.
  • Experience with cloud environments (AWS, Azure, GCP) and containerized workloads at scale.
  • Contributions to the security or software community through open-source projects, published research, conference talks, or similar.

Benefits

  • Time off programs
  • Medical, dental, vision, and mental health support
  • Paid parental leave
  • Life and disability insurance
  • 401(k) with company match
  • Employee stock purchasing program

More details about company benefits can be found at Salesforce Benefits.

Pay

The typical base salary range for this position is $172,500 - $260,100 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range is $207,800 - $285,800 annually. The range represents base salary only and does not include company bonus, incentive for sales roles, equity, or benefits.

Similar jobs