Jobs / United States / Salesforce INC
Lead Threat Assessment Engineer
Salesforce INC · 🇺🇸 4 Locations
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Salesforce INC paid sponsored hires in similar roles45 certified filings for “Senior Technical Support Engineer” (Software Quality Assurance Analysts and Testers) in TX: $118k–$148k, median $132k. Most were filed at wage level III (67%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Salesforce INC
The US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Salesforce INC →
About the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Enterprise Technology & Infrastructure Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. The Experience As a Lead Threat Assessment Engineer on the Environmental Threat Assessment team, you serve as an assessment lead and subject matter expert, supporting and building how we identify and mitigate threats across our global infrastructure. You will not only execute complex threat assessments but also mentor a team of junior analysts and engineers, helping to scale our capabilities through automation and "agentic" security investments. Your work will directly shape Salesforce’s security posture by translating deep technical research into actionable requirements for Product & Enterprise Security partners and Product/Engineering stakeholders. This role is within the Cybersecurity Operations Center vertical of Salesforce Security. What You'll Actually Be Doing: • Conducting threat modeling for infrastructure and application-level threat scenarios, including security architecture, system interactions, and new products/features from an observed/realized threat and outside-in perspective. • Utilizing threat intelligence, incident response and detection telemetry, proprietary security tooling, and internal security and risk signals to correlate research and manage Salesforce’s top threats program. • Analyzing logs from endpoint, network, and other security tooling to identify potential gaps in coverage or hunting for bypassing of existing controls, across new and existing business units. • Engaging executive stakeholders across the company to translate assessments into actionable recommendations that shape the business and our products. • Driving uplifts identified from security incidents with Product and Enterprise Security partners and serving as an SME for Product teams during design solutioning. • Design and orchestrate new agentic tooling for the team analysis capabilities and projects, supported by frontier harnesses, org-specific skills, and human workflows. • Providing strategic and tactical applied threat insights to Security and leadership stakeholders by contextualizing intelligence in Salesforce context in partnership with Threat Intelligence. • Collaborating with architects and principals across Cyber Security operations, including Threat Detection and Data Science, to design alerting against realized threats. You're Our Person If You Have: • 8+ years of experience in threat modeling and security architecture. • Significant understanding of threat actor tactics and offensive strategies and strong research and analytical skills with the ability to correlate data from various sources. • Experience using threat modeling and analysis frameworks such as Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and STRIDE, and familiarity with application security, specifically with the OWASP Top 10 vulnerabilities. • In-depth knowledge of cloud security and cloud architecture fundamentals and strong understanding of common exploitation and abuse threats observed across for SaaS and Paa