Mergers & Acquisitions Security Lead
SalesforceAbout the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Trust and security are Salesforce's number one value. We have built a mergers & acquisitions security integration team that is responsible for ensuring the security uplift of all Salesforce acquisitions. The Mergers & Acquisitions Security Lead will work with potential acquisition targets and completed acquisitions to threat model their environment, uncover risks, identify and track mitigations, and transition the acquisition to other security teams for long-term integration ownership.
We are looking for an individual contributor that wants to leverage their deep product security, penetration testing, development, operations, and infrastructure skills in a fast-paced and elite security environment. You are right for this job if you possess the unique skillset of product / infrastructure security testing skills partnered with excellent executive presence and communication. You will work with Salesforce and acquisition leadership and engineering teams to ensure product and infrastructure are secure. The work involved will be focused largely on product and infrastructure design and assessment, code review, threat modeling, assisting acquisition engineering teams integrating to Salesforce standards, and assisting acquisition engineering teams remediating issues uncovered during testing, among others.
Our ideal candidate has held a range of product security roles, has experience understanding business drivers and presenting to executive audiences, possesses strong written and verbal communication skills, creatively applies their technical acumen to a wide breadth of offensive and defensive security scenarios, is comfortable managing through ambiguity, and loves to get things done with an owner and driver mindset. If you like wearing multiple hats, knocking down doors to peek into dark corners to uncover security tech debt, developing plans to remediate risk, constantly learning about new and cutting edge technologies, and working with a team of passionate and kind security experts, this is the perfect role for you.
Salesforce makes multiple acquisitions per year, and each acquisition represents the unknown, ensuring engaging and exciting work that will challenge you technically and provide great opportunities to grow your professional skill set.
Travel: ~20%
YOUR IMPACT - RESPONSIBILITIES
As the M&A Security Lead Engineer, you are responsible for:
- Leading and conducting security diligence exercises for potential acquisition targets, including:
- Creating threat model of the target environment;
- Leading a team of security engineers in penetration testing and security review of target source code, infrastructure, cloud accounts, and other assets;
- Crafting and leading security-focused interviews with acquisition leadership and security resources;
- Requesting and analyzing supplemental information to build a full picture of a target’s security posture and areas of weakness;
- Identifying potential areas of risk and assessing their potential impact to Salesforce upon acquisition;
- Modeling out the potential real and opportunity costs of security debt on overall business priorities and deal models;
- Updating leadership and executives on status, findings, and potential risks throughout the exercise;
- Escalating critical areas of risk to acquisition and Salesforce leadership; and
- Using diligence information to craft preliminary integration plans.
- Leading security integrations of acquired companies, including:
- Using information discovered during diligence to craft detailed integration plans to drive the resolution of identified security debt
- Prioritizing work items in accordance with risk;
- Negotiating with work teams to estimate associated effort and ensure committed timelines for development and required work;
- Taking ownership for key milestones where possible and delegating or influencing partner engineering
- Leading security integrations of acquired companies, including:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s