Full-Time

Product Security Lead

Posted on 3/12/2025

Salesforce

Salesforce

10,001+ employees

Cloud-based Customer Relationship Management solutions

Compensation Overview

$184k - $253k/yr

+ Incentive Compensation + Equity

Senior, Expert

Company Historically Provides H1B Sponsorship

Seattle, WA, USA + 3 more

More locations: McLean, VA, USA | Reston, VA, USA | Burlington, MA, USA

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
PHP
Microsoft Azure
Python
JavaScript
Ruby
Java
TypeScript
AWS
Go
Google Cloud Platform
Requirements
  • Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
  • 8+ years validated experience in the following areas in a security engineering or research role:
  • Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
  • Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc.
  • Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.
  • Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript
  • Threat modeling of security topics across infrastructure security & application security domains
  • Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
  • Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, and intelligently to partners from a variety of backgrounds, including those who are non-technical.
Responsibilities
  • Partner with engineering teams; performing architecture risk analysis to proactively identify security flaws and develop risk mitigation plans to reduce risk throughout the SDLC.
  • Brainstorm with counterparts in the product teams to influence security improvements upstream. Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements.
  • Collaborate with Product BISOs to curate a highly aligned set of risk based security priorities to drive security maturity across the products.
  • Ability to advise on securing large, sophisticated enterprise architectures or systems deployed in public cloud environments across the application or infrastructure stack.
  • Research new technologies, emerging threats, and vulnerabilities to perform business impact analysis.
  • Analyze risk signals from diverse risk discovery data sources to derive crucial insights that will define the security activities and roadmap for Salesforce products.
  • Use product knowledge and deep security expertise to support risk prioritization activities across various security programs.
Desired Qualifications
  • Experience with client side/browser security features like same origin policy, CORS, CSP, shadow DOM, Web Components, web development frameworks etc.
  • An attacker’s approach; consider abuse and charge paths as well as the defensive mentality to recommendations to prevent them
  • A passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.
  • Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns
  • Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle
  • Some experience performing penetration testing or familiarity with the process

Salesforce provides cloud-based software solutions focused on Customer Relationship Management (CRM). Its main product, Customer 360, includes a suite of applications that help businesses manage marketing, sales, service, commerce, and IT operations, allowing for personalized customer interactions. The software operates on a subscription model, which means clients pay a recurring fee to access the services without needing to invest in hardware or software installations. This model supports continuous updates and improvements to the platform. Salesforce distinguishes itself from competitors by offering customizable solutions tailored to various industries, ensuring that businesses can find the right tools for their specific needs. The company's goal is to enhance customer relationships and drive growth for businesses of all sizes by providing effective CRM solutions.

Company Size

10,001+

Company Stage

IPO

Headquarters

San Francisco, California

Founded

1999

Simplify Jobs

Simplify's Take

What believers are saying

  • AI-driven customer service enhancements are a key focus for Salesforce.
  • Collaboration with Ather Energy highlights growth in industry-specific CRM solutions.
  • $1 billion investment in Singapore expands Salesforce's presence in Southeast Asia.

What critics are saying

  • Increased competition from AI-driven CRM solutions could erode market share.
  • Recent layoffs may impact Salesforce's ability to innovate and maintain service levels.
  • AI integration may face challenges in data privacy and compliance.

What makes Salesforce unique

  • Salesforce's Customer 360 offers a comprehensive suite of CRM applications.
  • The subscription-based model provides a steady revenue stream and continuous innovation.
  • Salesforce tailors solutions to meet specific industry needs, enhancing customer satisfaction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Life Insurance

401(k) Retirement Plan

Remote Work Options

Flexible Work Hours

Parental Leave

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

-1%
CDO Trends
Mar 17th, 2025
AI Flies To New Horizons On Board SIA

Singapore Airlines (SIA) is readying an army of AI agents to handle customer inquiries while simultaneously announcing a research partnership with tech giant Salesforce to develop next-generation AI solutions for the airline industry.

YourStory
Mar 17th, 2025
Salesforce, Ather Energy partner to streamline dealership operations

Salesforce on Monday partnered with IPO-bound electric two-wheeler maker Ather Energy to launch the automotive dealer management system - a new platform to enhance dealership operations and customer experience across India.

Travel and Tour World
Mar 16th, 2025
Vietnam Airlines partners with Sabre for global expansion

Singapore Airlines is also making strides in digital transformation by integrating AI-powered customer service solutions in partnership with Salesforce.

AI Customer Digest
Mar 16th, 2025
Salesforce and TripADeal introduce new AI-powered travel showcase

Salesforce and TripADeal introduce new AI-powered travel showcase.

Marketing Interactive
Mar 14th, 2025
Singapore Airlines picks Salesforce for AI-powered customer service

This collaboration will integrate Salesforce technologies, including Agentforce, Einstein in Service Cloud, and Data Cloud into Singapore Airlines' customer case management system, with an aim to enhance the personalisation and consistency of customer services provided by the airline.

INACTIVE