Lead Security Consultant - Professional Services Security Assurance (PSSA)
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job CategoryCustomer Success
Job DetailsSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
About The TeamWe are building a brand new Professional Services Security Assurance (PSSA) team - a true 0 to 1 opportunity. This team sits within the Security Practice, part of the broader Professional Services organization. Our mission is to empower the Professional Services organization to deliver secure implementations and protect customer data at scale.
We focus on securing the configurations, integrations, and implementations delivered to our customers. As a founding, hands-on technical member of the Security Assurance team within our Security Practice, you will deliver direct security engagements to our customers, ensuring every deployment is secure by design - and shaping the strategic foundation of our practice.
Role OverviewAs a hands-on technical expert, you will act as a force multiplier for our PSSA organization. Your primary focus is the delivery of high-impact security engagements directly to our customers, translating complex technical risks into actionable security postures.
What You’ll Do- Lead customer engagements by performing in-depth, high-quality security assessments of web, mobile, API, cloud, and AI-enabled applications - including architecture and design reviews, threat modeling, secure code reviews, and penetration testing.
- Conduct threat modeling exercises to identify potential attack vectors, evaluate business risk, and recommend security controls that effectively balance security, usability, and business objectives.
- Develop comprehensive security assessment reports that clearly communicate findings, risk ratings, and actionable remediation recommendations to both technical and executive stakeholders.
- Serve as a trusted security advisor to customers by providing practical remediation guidance, security best practices, and recommendations that improve the overall security posture of their applications and services.
- Collaborate closely with the professional services org to integrate security throughout the software development lifecycle, from design through deployment.
- Develop and enhance assessment methodologies, automation, and security tooling to improve assessment quality, consistency, and scalability across customer engagements.
- Define and contribute to technical security standards, reference architectures, and secure development guidelines in partnership with internal teams and customers.
- Research emerging technologies, evolving attack techniques, and security vulnerabilities to continuously improve assessment methodologies and provide proactive security recommendations.
- Build strong customer relationships through effective communication, technical leadership, and consultative engagement throughout the assessment lifecycle.
- Senior: 5+ years of experience in Application Security, Product Security, or Security Consulting
- Lead: 8+ years of experience in Application Security, Product Security, or Security Consulting
- Hands-on experience performing application security assessments, including architecture and design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews.
- Strong understanding of common application security vulnerabilities and secure development practices, including the OWASP Top 10, API Security Top 10, and common attack techniques.
- Experience assessing modern application architectures, including web…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).