To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.
About Salesforce
We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM+Trust. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place!
About Our Team
We are hiring a Lead Product Security Engineer for our Product Security Advisory team. Our mission is to reduce security risks and ensure compliance with standards, regulations, and certifications across all Salesforce products.
Our team provides deep technical expertise in architecture and infrastructure to our Business Units. We offer security advisory services, actionable SDLC standard methodologies, and critical risk treatment recommendations. We secure a wide range of technologies, both on-premise and in public cloud environments, including web applications, distributed systems, and virtualized environments. This role supports engineering across full stack, ensuring the security of customer-facing products!
Impact - Responsibilities
Partner with engineering teams; performing architecture risk analysis to proactively identify security flaws and develop risk mitigation plans to reduce risk throughout the SDLC.
Brainstorm with counterparts in the product teams to influence security improvements upstream. Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements.
Collaborate with Product BISOs to curate a highly aligned set of risk based security priorities to drive security maturity across the products.
Ability to advise on securing large, sophisticated enterprise architectures or systems deployed in public cloud environments across the application or infrastructure stack.
Research new technologies, emerging threats, and vulnerabilities to perform business impact analysis.
Analyze risk signals from diverse risk discovery data sources to derive crucial insights that will define the security activities and roadmap for Salesforce products.
Use product knowledge and deep security expertise to support risk prioritization activities across various security programs.
Minimum qualifications
Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
5+ years validated experience in the following areas in a security engineering or research role:
Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc.
Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc.
Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript
Threat modeling of security topics across infrastructure security & application security domains
Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
Strong writing and presentation skills. Possess the ability to communicate concisely, clearly, and intelligently to partners from a variety of backgrounds, including those who are non-technical.
Preferred Qualifications
Experience with client side/browser security features like same origin policy, CORS, CSP, shadow DOM, Web Components, web development frameworks etc.
An attacker’s approach; consider abuse and charge paths as well as the defensive mentality to recommendations to prevent them
A passion around improving the security development lifecycle and delivering security mentorship to engineers in a language they understand.
Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns
Experience leading or participating in an information security program and improving or proposing improvements to a secure development lifecycle
Some experience performing penetration testing or familiarity with the process
*LI-Y
Accommodations
If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.
Posting Statement
At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.
Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.
Salesforce welcomes all.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.For Washington-based roles, the base salary hiring range for this position is $176,800 to $243,100.For California-based roles, the base salary hiring range for this position is $192,900 to $265,200.Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: https://www.salesforcebenefits.com.Other Jobs from Salesforce
Technical Support Engineer, Service Cloud
Sr. Director Engineering
Director, Network Security Engineering
Manager, Technical Consulting (Salesforce Technical Architect Experience Mandatory)
2025 Intern - Software Engineer
Director, Solution Engineering, Salesforce National Security
Similar Jobs
Full Stack Engineer
Ruby on Rails Software Engineer (Guadalajara)
Staff Front-End Engineer - Robotics
Software Development Engineer
Senior Application Security Engineer (PHP)
Senior Application Security Engineer (JavaScript/TypeScript)
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 401 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say