Enterprise Security Senior Manager (Technology BISO org)
SalesforceAbout the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & InfrastructureJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!
About Our Team
Salesforce's Enterprise Security team is at the forefront of enterprise IT, focusing on collaboration with business partners to achieve outstanding outcomes. We lead technology strategy, Salesforce on Salesforce, customer and partner enablement, applications engineering, infrastructure, collaboration, enterprise operations, architecture, and program enablement.
We are seeking a dedicated and dynamic Risk Management and Information Security Senior Manager to join our Enterprise Technology Risk Management team. This role involves advising partners on security control design, process improvements, and implementing information security controls within various compliance frameworks.
The ideal candidate will motivate change, lead readiness and process/control improvement initiatives, communicate and support recommendations effectively, and influence action in a multi-functional environment. Strong business and information security competence, a consistent track record in advising on control design and process improvements, and the ability to transform business knowledge into scalable solutions are needed!
Impact - Responsibilities
Security Strategy Alignment: Partner with Technology unit leaders to embed information security controls into the system lifecycle, ensuring security controls support operational efficiency and innovation.
Risk Assessment and Management: Conduct risk assessments for IT systems, applications, and processes. Identify vulnerabilities, recommend mitigations, and prioritize remediation efforts based on business impact.
Policy and Compliance Implementation: Translate enterprise security policies into actionable controls tailored to the technology unit you support. Ensure compliance with relevant regulations (e.g., GDPR, CCPA, PCI DSS) and industry standards (e.g., NIST 800-53, ISO 27001).
Control Readiness Reviews: Lead the execution of all phases within a system control readiness lifecycle, ensuring timely delivery and quality work. Supervise functional teams for compliance to outlined processes and ensure that all key controls are being performed satisfactorily
Metrics and Reporting: Develop and maintain key performance indicators (KPIs) and key risk indicators (KRIs) for Technology units security posture. Provide regular reports to midlevel leadership.
Compliance Advisory: Experience designing, implementing, and testing internal controls in response to identified risks and how to partner with external or internal audit functions.
Minimum Qualifications
Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field. Equivalent experience may be considered.
Minimum of 10 years of experience in information security, with at least 5 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third-party integrations.
Deep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third-party risk management frameworks
Familiarity with security tools s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s