Enterprise Security BISO - Director
SalesforceAbout the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & InfrastructureJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Job Title: Enterprise Security BISO - Director (IC)
About the Role:
The Business Information Security Officer - Director role is part of our Enterprise Security Team. This role will act as a pivotal liaison between the Enterprise Security team and technology business units, ensuring alignment of security controls, policies, and strategies with organizational goals. To drive reduction of risk throughout the enterprise, this role requires both a strategic lens, as well as an engineering mindset, including technical knowledge in secure development and architecture. As an individual contributor, the BISO will drive security initiatives, ensure foundational control compliance, influence strategic investment opportunities and policy changes, and provide strategic guidance to their assigned business units.
Your Impact - Responsibilities:
Strategic Security Alignment: Partner with business units to integrate cybersecurity strategies into business processes, ensuring alignment with organizational objectives and risk tolerance through secure-by-design integration. Embed security into business unit roadmaps by reviewing PRDs, architectural diagrams and CI/CD pipelines in real time; reject weak patterns (i.e. default-deny not enforced, secrets in code).
Risk Management and Compliance: Conduct technology tier 3 risk assessments, identify security control gaps, and develop mitigation strategies in alignment with industry standards. Manage stakeholder expectations and cybersecurity risk for the Business units.
Security Architecture Oversight: Provide technical guidance on secure development patterns. For example, basic guidance understanding of firewalls, intrusion detection/prevention systems (IDS/IPS), SDLC, threat modeling, secure authentication and authorization and endpoint detection and response (EDR), and security information and event management (SIEM) systems. . Embed security into business unit roadmaps by reviewing PRDs, architectural diagrams and CI/CD pipelines in real time, rejecting weak patterns (i.e. default-deny not enforced, secrets in code).
Policy Development and Governance: Refine, and enforce security policies, standards, and procedures, which are applicable to the enterprise environment, ensuring compliance with regulations and emerging risks. Own risk evaluation of security policy exceptions within the assigned BUs.
Strategic Security Remediation Risk Prioritization: Lead the coordination of security remediation efforts for business units, through a risk register which helps prioritize all work (bugs, transformational initiatives, compliance findings, etc) during sprint planning.
Stakeholder Relationship Management: Build and maintain strong relationships with business leaders, IT teams, and external partners to foster a culture of security awareness and collaboration. Influence strategic security investment decision-making without direct authority and work effectively across different teams and at all levels.Influence leadership when strategic investments are needed.
Security Awareness and Training: Develop and deliver tailored security awareness programs for business units as applicable, promoting best practices in areas such as phishing prevention and secure data handling, when needed.
Security Posture Analytics: Create dashboards for KPIs and KRIs that highlight actionable insights (e.g., vulnerability trends triggering automated alerts), presenting to leadership to inform business unit wide security improvements.
Metrics and Reporting: Develop and present key performance indicators (KPIs) and key risk indicators (KRIs) to senior lead
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s