Product Security Lead
Salesforce
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!
About Our Team
We are hiring a Lead Product Security Engineer for our Product Security Advisory team. Our mission is to reduce security risks and ensure compliance with standards, regulations, and certifications across all Salesforce products.
Our team provides deep technical expertise in architecture and infrastructure to our Business Units. We offer security advisory services, actionable SDLC standard methodologies, and critical risk treatment recommendations. We secure a wide range of technologies, both on-premise and in public cloud environments, including web applications, distributed systems, and virtualized environments. This role supports engineering across full stack, ensuring the security of customer-facing products!
Impact - Responsibilities
Partner with engineering teams; performing architecture risk analysis to proactively identify security flaws and develop risk mitigation plans to reduce risk throughout the SDLC.
Brainstorm with counterparts in the product teams to influence security improvements upstream. Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements.
Collaborate with Product BISOs to curate a highly aligned set of risk based security priorities to drive security maturity across the products.
Ability to advise on securing large, sophisticated enterprise architectures or systems deployed in public cloud environments across the application or infrastructure stack.
Research new technologies, emerging threats, and vulnerabilities to perform business impact analysis.
Analyze risk signals from diverse risk discovery data sources to derive crucial insights that will define the security activities and roadmap for Salesforce products.
Use product knowledge and deep security expertise to support risk prioritization activities across various security programs.
Minimum qualifications
Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
-
5+ years validated experience in the following areas in a security engineering or research role:
Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc.
Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.
Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript
Threat modeling of security topics across infrastructure security & application security domains
Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, and intelligently to partners from a variety of backgrounds, including those who are non-technical.
Preferred Qualifications
Experience with client side/browser security features like same origin policy, CORS, CSP, shadow DOM, Web Components, web development frameworks etc.
An attacker’s approach; consider abuse and charge paths as well as the defensive mentality to recommendations to prevent them
A passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.
Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns
Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle
Some experience performing penetration testing or familiarity with the process
*LI-Y
Accommodations
If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.
Posting Statement
At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.
Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.
Salesforce welcomes all.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.For Washington-based roles, the base salary hiring range for this position is $176,800 to $243,100.For California-based roles, the base salary hiring range for this position is $192,900 to $265,200.Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: https://www.salesforcebenefits.com.