Demo

Product Security Lead

salesforce.com, inc.
San Francisco, CA Full Time
POSTED ON 12/2/2024
AVAILABLE BEFORE 2/2/2025

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Product

Job Details

About Salesforce

We're Salesforce, the Customer Company, inspiring the future of business with AI Data CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too - driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good - you've come to the right place.

About Salesforce

We're Salesforce, the Customer Company, inspiring the future of business with AI Data CRM Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too - driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good - you've come to the right place!

About Our Team

We are hiring a Lead Product Security Engineer for our Product Security Advisory team. Our mission is to reduce security risks and ensure compliance with standards, regulations, and certifications across all Salesforce products.

Our team provides deep technical expertise in architecture and infrastructure to our Business Units. We offer security advisory services, actionable SDLC standard methodologies, and critical risk treatment recommendations. We secure a wide range of technologies, both on-premise and in public cloud environments, including web applications, distributed systems, and virtualized environments. This role supports engineering across full stack, ensuring the security of customer-facing products!

Impact - Responsibilities

  • Partner with engineering teams; performing architecture risk analysis to proactively identify security flaws and develop risk mitigation plans to reduce risk throughout the SDLC.

  • Brainstorm with counterparts in the product teams to influence security improvements upstream. Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements.

  • Collaborate with Product BISOs to curate a highly aligned set of risk based security priorities to drive security maturity across the products.

  • Ability to advise on securing large, sophisticated enterprise architectures or systems deployed in public cloud environments across the application or infrastructure stack.

  • Research new technologies, emerging threats, and vulnerabilities to perform business impact analysis.

  • Analyze risk signals from diverse risk discovery data sources to derive crucial insights that will define the security activities and roadmap for Salesforce products.

  • Use product knowledge and deep security expertise to support risk prioritization activities across various security programs.

Minimum qualifications

  • Bachelor's degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required

  • 5 years validated experience in the following areas in a security engineering or research role:

    • Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25

    • Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc.

    • Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.

  • Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript

  • Threat modeling of security topics across infrastructure security & application security domains

  • Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements

  • Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, and intelligently to partners from a variety of backgrounds, including those who are non-technical.

Preferred Qualifications

  • Experience with client side/browser security features like same origin policy, CORS, CSP, shadow DOM, Web Components, web development frameworks etc.

  • An attacker's approach; consider abuse and charge paths as well as the defensive mentality to recommendations to prevent them

  • A passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.

  • Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns

  • Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle

  • Some experience performing penetration testing or familiarity with the process

*LI-Y



Accommodations

If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.

Posting Statement

At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.

Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.

Salesforce welcomes all.

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

For Washington-based roles, the base salary hiring range for this position is $176,800 to $243,100.

For California-based roles, the base salary hiring range for this position is $192,900 to $265,200.

Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: https://www.salesforcebenefits.com.
Salesforce.com and Salesforce.org are Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this Web site or directly to managers. Salesforce.com and Salesforce.org do not accept unsolicited headhunter and agency resumes. Salesforce.com and Salesforce.org will not pay fees to any third-party agency or company that does not have a signed agreement with Salesforce.com or Salesforce.org.

 

Salary : $176,800 - $243,100

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Product Security Lead?

Sign up to receive alerts about other jobs on the Product Security Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$101,856 - $146,479
Income Estimation: 
$73,266 - $131,599
Income Estimation: 
$148,382 - $214,197
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553

Sign up to receive alerts about other jobs with skills like those required for the Product Security Lead.

Click the checkbox next to the jobs that you are interested in.

  • Bug/Defect Analysis Skill

    • Income Estimation: $101,441 - $130,752
    • Income Estimation: $102,541 - $137,871
  • Code Optimization Skill

    • Income Estimation: $187,647 - $219,963
    • Income Estimation: $187,890 - $240,773
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at salesforce.com, inc.

salesforce.com, inc.
Hired Organization Address Indianapolis, IN Full Time
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you a...
salesforce.com, inc.
Hired Organization Address Indianapolis, IN Full Time
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you a...
salesforce.com, inc.
Hired Organization Address Indianapolis, IN Full Time
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you a...
salesforce.com, inc.
Hired Organization Address Seattle, WA Full Time
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you a...

Not the job you're looking for? Here are some other Product Security Lead jobs in the San Francisco, CA area that may be a better fit.

Sr/Lead/Staff Product Manager

Lead Discovery GmbH, San Francisco, CA

Product Security Lead

EOS, San Francisco, CA

AI Assistant is available now!

Feel free to start your new journey!