Product Security Lead
SalesforceAbout the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!
About Our Team
We are hiring a Lead Product Security Engineer for our Product Security Advisory team. Our mission is to reduce security risks and ensure compliance with standards, regulations, and certifications across all Salesforce products.
Our team provides deep technical expertise in architecture and infrastructure to our Business Units. We offer security advisory services, actionable SDLC standard methodologies, and critical risk treatment recommendations. We secure a wide range of technologies, both on-premise and in public cloud environments, including web applications, distributed systems, and virtualized environments. This role supports engineering across full stack, ensuring the security of customer-facing products!
Impact - Responsibilities
Partner with engineering teams; performing architecture risk analysis to proactively identify security flaws and develop risk mitigation plans to reduce risk throughout the SDLC.
Brainstorm with counterparts in the product teams to influence security improvements upstream. Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements.
Collaborate with Product BISOs to curate a highly aligned set of risk based security priorities to drive security maturity across the products.
Ability to advise on securing large, sophisticated enterprise architectures or systems deployed in public cloud environments across the application or infrastructure stack.
Research new technologies, emerging threats, and vulnerabilities to perform business impact analysis.
Analyze risk signals from diverse risk discovery data sources to derive crucial insights that will define the security activities and roadmap for Salesforce products.
Use product knowledge and deep security expertise to support risk prioritization activities across various security programs.
Minimum qualifications
Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
5+ years validated experience in the following areas in a security engineering or research role:
Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc.
Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.
Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript
Threat modeling of security topics across infrastructure security & application security domains
Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s