Jobs and Careers
SA

Product Security Principal

Salesforce
San Francisco, United Statesfull_timeVerifiedPosted 18 Aug 2025
💰 $334,600/yr($230,800/yr$334,600/yr)

About the role

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Product

Job Details

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Job Title: Foundations Security Engineer - Principal Security Engineer

About the Role

Are you a visionary security leader passionate about shaping the security posture of critical cloud infrastructure and developer tooling at an enterprise scale? As a Lead or Principal Security Engineer within the Product Security Foundations team, you will be the driving force behind safeguarding Salesforce's foundational systems. In this highly impactful role, you will leverage your deep expertise in public cloud security (AWS and GCP) to drive risk reduction initiatives, fortify our cloud substrate configurations, and secure services deployed across our multi-cloud environment. Your expertise will be crucial in securing cloud infrastructure, including AWS and GCP substrate configurations and services deployed there. Additionally, you will apply your security leadership to fortify our build infrastructure services, including CI/CD pipelines and Source Code Management (SCMs), ensuring the integrity and security of our development processes. This is a unique opportunity to lead strategic security initiatives, discover and remediate systemic risks, and mentor other engineers, directly contributing to the security posture of one of the world's leading enterprise cloud companies.

Your Impact - Responsibilities

  • Lead Cloud Security Strategy: Architect, and drive security best practices across Salesforce's extensive public cloud infrastructure (AWS and GCP), ensuring robust configurations and secure deployments of critical services.

  • Systemic Risk Discovery, Remediation & Secure Cloud Substrate: Conduct in-depth security assessments to identify systemic vulnerabilities and recommend effective, scalable remediation strategies that span across our cloud ecosystem and product offerings. Deep dive into public cloud substrate configurations, ensuring the highest level of security for underlying infrastructure components and services.

  • Fortify Developer Infrastructure: Architect, and drive robust security controls for our essential Developer Infrastructure, including critical CI/CD pipelines, artifact repositories, and Source Code Management (SCM) systems, to maintain the integrity and security of our development processes.

  • Drive Security Innovation: Lead the research, evaluation, and adoption of cutting-edge security technologies and methodologies, driving the implementation of innovative solutions that significantly enhance Salesforce's overall security posture.

  • Cross-Functional Collaboration: Partner closely with engineering, operations, and product teams to embed security early in the development lifecycle and ensure security requirements are met.

  • Incident Response & Prevention: Contribute to incident response efforts related to cloud and infrastructure security, focusing on root cause analysis and implementing preventative measures.

Minimum Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field. Equivalent experience may be considered.

  • 10+ years of experience in security engineering, with a significant portion focused on cloud security in large-scale enterprise environments.

  • Deep expertise in public cloud security across both AWS and GCP, including strong understanding of their security services, architecture, and best practices (e.g., IAM, network security, data encryption, compliance, configuration management).

  • Proven ability to identify, analyze, and drive the remediation of systemic security vulnerabilities and risks across complex systems.

  • Strong understanding of developer infrastructure security, including CI/CD pipelines, artifact repositories, a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Salesforce

View company profile →