Offensive Security- Red Team

Momentum
Momentum

Tel Aviv-Yafo, Israel

Posted on Oct 8, 2026

The Experience
Join the Product Security team in Israel as an Offensive Security Engineer on our Red Team. You partner with the Red Team Director to run realistic attack simulations across Salesforce products, platforms, and enterprise environments, and you help make our defenses stronger, including as AI and Agentforce reshape our attack surface.

What You'll Actually Be Doing

  • Run hands-on red team operations that simulate real-world attackers across applications, cloud, and enterprise environments, and chain weaknesses together to reach defined goals.
  • Design and carry out end-to-end attack campaigns with the Red Team Director, including bypassing security controls and abusing identity, access, and trust relationships.
  • Work with Detection and Response, Incident Response, and Engineering teams to test alerts and response workflows, and explain attack paths and root causes in clear, practical terms.
  • Improve red team tools, automation, and techniques with the AI-Automation team, and mentor junior engineers.



You're Our Person If...

  • You have 4+ years of experience in offensive security, red teaming, or advanced penetration testing in production-like environments.
  • You understand attacker methods, identity and access abuse, and attack chains across applications, infrastructure, cloud, and hybrid environments.
  • You write custom scripts, tools, or payloads, and you are skilled at manual exploitation.
  • You communicate clearly about how an attack worked, why defenses failed, and which fixes reduce risk most.
  • Degree or equivalent relevant experience required. Experience will be evaluated based on the core competencies for the role (e.g. extracurricular leadership roles, military experience, volunteer roles, work experience, etc.)



Even Better If...

  • You have run continuous or programmatic red team operations, or have a background in adversary emulation or purple team work.
  • You have experience with malware analysis or exploit development.
  • You have published vulnerability research, responsible disclosures, blogs, or talks.
  • You know cloud-native architectures and identity-centric security models.