Jobs and Careers
SA

BISO - US Public Sector Cloud Services, Senior Director

Salesforce
San Francisco, United Statesfull_timeVerifiedPosted 19 Aug 2024
💰 $372,900/yr($224,100/yr$372,900/yr)

About the role

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Product

Job Details

About Salesforce

We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.

About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!

About Our Team
In the capacity of the Business Information Security Officer (BISO) for Salesforce services on the Government Cloud platform, you will be pivotal in ensuring that Salesforce's US public sector offerings, especially within the police sector, comply with regulatory and security obligations. You will collaborate closely with product engineering, operations, Public Sector compliance, and Government Accreditation teams to oversee and report on security compliance. This role requires a proactive stance in assessing security posture, offering expert guidance, and devising solutions to meet the rigorous standards of government agencies.

Impact - Responsibilities 

  • Ensure compliance with Salesforce US public sector obligations by collaborating with relevant teams on the Government Cloud platform

  • Build and maintain relationships as a trusted security partner with product engineering and operations teams in the US public sector

  • Track, report, and escalate compliance status. Partner closely with the US Public Sector Government Accreditation and compliance team for successful reporting and certification renewals

  • Continuously assess security posture with a security-by-default mindset. Provide risk reduction recommendations through threat modeling, design reviews, code reviews, and mitigation documentation

  • Manage multiple impactful and complex security projects, ensuring alignment with internal security requirements

  • Engage in deep architectural discussions to ensure successful deployment or migration of cloud infrastructures, applications, software, and services

  • Evaluate emerging threats and attacks, develop and implement appropriate security controls

  • Partner with engineering teams and advise on security best practices when integrating CI/CD pipeline tools, test plans, and vulnerability assessment tools

  • Work with product teams to develop custom security solutions addressing identified risks

  • Provide guidance on developing solutions that prevent similar issues categorically

  • Implement opportunities to automate security processes where appropriate


Minimum Qualifications

  • BA or BS in Computer Science or any related subject area, or 10+ years of experience

  • A minimum of 10 years of relevant work experience, particularly in securing large, globally distributed cloud-based or mobile-embedded platforms

  • Knowledge of OWASP Top 10 vulnerabilities

  • Experience with Threat Modeling using frameworks

  • Experience with cross-matrix collaboration related to engineering, security and compliance topics

  • Experience with responding to security and compliance customer questionnaires and engaging with customer representatives on security- and compliance-related topics

Required Qualifications

  • Proven background in software engineering or development, with a focus on Application or Product Security

  • Strong Understanding of application architectures, design principles, common security flaws, and mitigation techniques as outlined by OWASP and SANS

  • Experience in building resilient, highly available systems

  • Demonstrated ability to evaluate system security, identify patterns, and investigate complex issues

  • Established ability to make data-drive

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Salesforce

View company profile →