Salesforce logo

Product Security Lead

Salesforce

CA and WAJobPosted 2 days agoStill listed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
CA and WA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Lead Product Security Engineer, Infrastructure joins Salesforce’s Infrastructure Product Security Assurance team to strengthen security across foundational services and core infrastructure platforms. The role provides strategic guidance to engineering teams, serves as a security partner to engineering and leadership, and advances secure software development practices across on-premises and public cloud environments.

Skills & qualifications

RequiredNice to have

Skills

Security EngineeringCloud Computing SecurityThreat ModelingRisk AnalysisIdentity Management SystemsAccess ControlsNetworking BasicsInterpersonal CommunicationsCloud SecurityCloud Service ModelsShared Responsibility ModelsIdentity PrimitivesSecurity Design ReviewsOWASP Top 10CWE Top 25Security Risk AssessmentOAuthOpenID ConnectSAMLService AuthenticationAPI AuthorizationTCP/IPTLSNetwork SegmentationKey ManagementCertificate Lifecycle ManagementSecrets HandlingEncryption StandardsWritten CommunicationVerbal CommunicationInfluencing Engineering TeamsAbuse Case AnalysisAttack Path AnalysisPenetration TestingOffensive SecuritySecure Development LifecycleSecurity Review ProcessesSecurity Advisory ProgramsStructured Data AnalysisPattern RecognitionCode ReadingJavaGoPythonKubernetesDockerIstio

Qualifications

8+ Years Security Engineering Experience

Benefits

Paid Time Off
Medical Insurance
Dental Insurance
Vision Insurance
Parental Leave
401(k) Match

Full job description

Description Job Title: Lead Product Security Engineer, Infrastructure Job Category: Technology / Security Location: San Francisco, CA or Bellevue, WA

The Experience

Join our Infrastructure Product Security Assurance team as a Lead Product Security Engineer, where you play a pivotal role in fortifying the bedrock of Salesforce's entire product ecosystem. In this highly impactful position, you leverage deep technical expertise to provide strategic security guidance and leadership to engineering teams responsible for our foundational services, including technical controls, infrastructure databases, and monitoring tools across public cloud platforms.

As a trusted security engineer, you serve as the primary point of contact for engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions directly shape and enhance the security posture of our core infrastructure platforms, ensuring the resilience and integrity of Salesforce's offerings.

Our team specializes in providing deep architectural and infrastructure security expertise across a diverse range of technologies, both on-premises and in public cloud environments, including web applications, distributed systems, and virtualized infrastructures. You champion secure software development lifecycle (SSDL) best practices, empowering engineering teams to build secure products from the ground up.

What You'll Actually Be Doing

  • Provide expert security advisory for large-scale cloud initiatives, offering strategic guidance to engineering teams on complex enterprise architectures across the application and infrastructure stack.
  • Drive proactive security through architecture and threat modeling, partnering with engineering teams to identify vulnerabilities and develop risk mitigation plans throughout the software development lifecycle (SDLC).
  • Influence secure design and implementation by collaborating with product teams to recommend design solutions that balance functional goals with security requirements.
  • Align security priorities with business risk by working with Product Business Information Security Officers (BISOs) to curate and prioritize risk-based security initiatives, and by analyzing risk signals and emerging threats to shape security roadmaps.

You're Our Person If...

  • You have 8-10 years of experience in a security engineering, security architecture, or security assurance role.
  • Cloud Security: You have experience securing products and infrastructure across one or more public cloud environments (Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, or equivalent), with an understanding of cloud service models, shared responsibility boundaries, and identity primitives at scale.
  • Threat Modeling & Risk Assessment: You have experience conducting structured security design reviews and threat modeling across infrastructure and application security domains, with familiarity with common vulnerability classes (Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE) Top 25), and can evaluate and communicate security risk to technical and non-technical audiences alike.
  • Identity, Access, and Network Fundamentals: You understand authentication and authorization patterns including Open Authorization (OAuth) / OpenID Connect (OIDC), Security Assertion Markup Language (SAML), service-to-service authentication, and API authorization models, as well as TCP/IP, Transport Layer Security (TLS), network segmentation, and key management, certificate lifecycles, secrets handling, and encryption standards.
  • You have strong written and verbal communication skills, with the ability to influence engineering teams toward secure outcomes without relying on direct organizational authority.

Even Better If...

  • You can reason through abuse cases and attack paths, not just defensive recommendations, with some familiarity with penetration testing methodologies or offensive security techniques.
  • You have experience participating in or driving improvements to a secure development lifecycle, security review process, or security advisory program within an engineering organization.
  • You can work with structured data, identify patterns across a broad service portfolio, and propose mitigations that address root causes rather than individual findings.
  • You can read and reason about code in one or more languages common in cloud-native engineering environments — particularly Java, Go, or Python — and have hands-on familiarity with container orchestration and workload security (Kubernetes, Docker, service mesh such as Istio), secrets/key management and Public Key Infrastructure (PKI) tooling, Cloud Security Posture Management (CSPM) and vulnerability scanning tools, or static analysis (SAST) and infrastructure-as-code security scanning.

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.