
Product Security Lead
CA and WAJobPosted 2 days agoStill listed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near CA and WA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Lead Product Security Engineer, Infrastructure joins Salesforce’s Infrastructure Product Security Assurance team to strengthen security across foundational services and core infrastructure platforms. The role provides strategic guidance to engineering teams, serves as a security partner to engineering and leadership, and advances secure software development practices across on-premises and public cloud environments.
Skills & qualifications
Skills
Qualifications
Benefits
Full job description
Description Job Title: Lead Product Security Engineer, Infrastructure Job Category: Technology / Security Location: San Francisco, CA or Bellevue, WA
The Experience
Join our Infrastructure Product Security Assurance team as a Lead Product Security Engineer, where you play a pivotal role in fortifying the bedrock of Salesforce's entire product ecosystem. In this highly impactful position, you leverage deep technical expertise to provide strategic security guidance and leadership to engineering teams responsible for our foundational services, including technical controls, infrastructure databases, and monitoring tools across public cloud platforms.
As a trusted security engineer, you serve as the primary point of contact for engineering partners and leadership, cultivating strong relationships and delivering critical security recommendations. Your contributions directly shape and enhance the security posture of our core infrastructure platforms, ensuring the resilience and integrity of Salesforce's offerings.
Our team specializes in providing deep architectural and infrastructure security expertise across a diverse range of technologies, both on-premises and in public cloud environments, including web applications, distributed systems, and virtualized infrastructures. You champion secure software development lifecycle (SSDL) best practices, empowering engineering teams to build secure products from the ground up.
What You'll Actually Be Doing
- Provide expert security advisory for large-scale cloud initiatives, offering strategic guidance to engineering teams on complex enterprise architectures across the application and infrastructure stack.
- Drive proactive security through architecture and threat modeling, partnering with engineering teams to identify vulnerabilities and develop risk mitigation plans throughout the software development lifecycle (SDLC).
- Influence secure design and implementation by collaborating with product teams to recommend design solutions that balance functional goals with security requirements.
- Align security priorities with business risk by working with Product Business Information Security Officers (BISOs) to curate and prioritize risk-based security initiatives, and by analyzing risk signals and emerging threats to shape security roadmaps.
You're Our Person If...
- You have 8-10 years of experience in a security engineering, security architecture, or security assurance role.
- Cloud Security: You have experience securing products and infrastructure across one or more public cloud environments (Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, or equivalent), with an understanding of cloud service models, shared responsibility boundaries, and identity primitives at scale.
- Threat Modeling & Risk Assessment: You have experience conducting structured security design reviews and threat modeling across infrastructure and application security domains, with familiarity with common vulnerability classes (Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE) Top 25), and can evaluate and communicate security risk to technical and non-technical audiences alike.
- Identity, Access, and Network Fundamentals: You understand authentication and authorization patterns including Open Authorization (OAuth) / OpenID Connect (OIDC), Security Assertion Markup Language (SAML), service-to-service authentication, and API authorization models, as well as TCP/IP, Transport Layer Security (TLS), network segmentation, and key management, certificate lifecycles, secrets handling, and encryption standards.
- You have strong written and verbal communication skills, with the ability to influence engineering teams toward secure outcomes without relying on direct organizational authority.
Even Better If...
- You can reason through abuse cases and attack paths, not just defensive recommendations, with some familiarity with penetration testing methodologies or offensive security techniques.
- You have experience participating in or driving improvements to a secure development lifecycle, security review process, or security advisory program within an engineering organization.
- You can work with structured data, identify patterns across a broad service portfolio, and propose mitigations that address root causes rather than individual findings.
- You can read and reason about code in one or more languages common in cloud-native engineering environments — particularly Java, Go, or Python — and have hands-on familiarity with container orchestration and workload security (Kubernetes, Docker, service mesh such as Istio), secrets/key management and Public Key Infrastructure (PKI) tooling, Cloud Security Posture Management (CSPM) and vulnerability scanning tools, or static analysis (SAST) and infrastructure-as-code security scanning.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Product Security LeadSalesforce · San Francisco, CA · $173–260K/yrPosted 3w agoPosted 3w ago
Director of Product SecurityHarvey · San Francisco, CA (Hybrid) · $272–408K/yrPosted 1w agoPosted 1w ago
Principal Product Security EngineerSalesforce · San Francisco, CA · $173–314K/yrPosted 1w agoPosted 1w agoPrincipal Product Manager - Platform SecurityPagerDuty · San Francisco, CA (Hybrid) · $180–304K/yrPosted 2w agoPosted 2w ago
Product Lead, InpatientAmbience Healthcare · San Francisco, CA (Hybrid) · $203–283K/yrPosted 3w agoPosted 3w ago
You've read the whole posting — now see how you match it.