Product Security Lead Advisor
Listed on 2026-02-08
-
IT/Tech
Cybersecurity, Systems Engineer, IT Consultant, Cloud Computing
Overview
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category Product
Job Details
About SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
AboutThe Role
Join our Infrastructure & Foundations Product Security Advisory team as a Lead Product Security Engineer, where you ll play a pivotal role in fortifying the bedrock of Salesforce s entire product ecosystem. In this highly impactful position, you ll leverage your deep technical expertise to provide strategic security guidance and leadership to engineering teams responsible for our foundational services, including core technical security controls, public cloud platforms, and build infrastructure.
As a trusted security advisor, you ll serve as the primary point of contact for our engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions will directly shape and enhance the security posture of our core platforms, ensuring the resilience and integrity of Salesforce s offerings.
Our team specializes in providing deep architectural and infrastructure security expertise across a diverse range of technologies, both on-premises and within public cloud environments. This includes securing web applications, distributed systems, and virtualized infrastructures. You ll champion secure software development lifecycle (SSDL) best practices, empowering engineering teams to build secure products from the ground up.
Responsibilities and ImpactProvide Expert Security Advisory for Large-Scale Cloud Initiatives:
Offer strategic security guidance to engineering teams on complex enterprise architectures and systems across the application and infrastructure stack within large-scale public cloud initiatives.
Drive Proactive Security Through Architecture and Threat Modeling:
Partner closely with engineering teams to conduct thorough architecture and threat modeling risk analyses, proactively identifying security vulnerabilities and developing comprehensive risk mitigation plans throughout the SDLC.
Influence Secure Design and Implementation:
Collaborate with product teams to influence upstream security improvements, balancing functional goals with security requirements by recommending optimal design solutions.
Align Security Priorities with Business Risk:
Work with Product BISOs to curate and prioritize risk-based security initiatives, driving security maturity across all products.
Conduct Continuous Threat and Technology Research:
Research emerging threats, vulnerabilities, and new technologies, performing business impact analyses to inform security strategies.
Analyze Risk Signals for Actionable Insights:
Analyze diverse risk discovery data sources to derive crucial insights, shaping security activities and roadmaps for Salesforce products.
Support Risk Prioritization Across Security Programs:
Leverage deep security expertise and product knowledge to support risk prioritization activities across various security programs.
Bachelor s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
5+ years proven experience in the following areas in a security engineering or research role:
Public Cloud security architecture in one or more of the following:
Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
Exploiting web and web services security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).