Product Security Lead
San Francisco, CAJobPosted 3w agoStill listed 3 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Francisco, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Product Security Lead will act as the technical security authority for Salesforce's experience and UI layers, guiding threat modeling, security design reviews, and code reviews across web frameworks and AI-driven components. The role shapes security standards, drives secure-by-default patterns, and leads multi‑team programs to protect guest‑user data and agentic interactions, collaborating closely with product and engineering teams.
Skills & qualifications
Skills
Benefits
Full job description
Description The Experience
Salesforce's Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on. We are hands-on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world's #1 CRM platform secure. This role serves as the technical security lead for the user-facing application and experience layers of the platform, including front-end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences. It also covers fast-growing AI agent-driven experiences and web data-access surfaces that render across our own surfaces, third-party channels, and external agentic clients. You'll set the security assurance bar across these areas. You'll shape how controls are designed and drive secure-by-default patterns upstream. You'll serve as a trusted security voice to a top-tier Engineering organization delivering multi-release, cross-team programs, at a time when this layer's trust model is being redefined.
What You'll Actually Be Doing
- Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them.
- Serve as the standing security lead for multi-quarter, multi-team programs such as the expansion of guest-user data access, first-party experiences rendering into surfaces we don't control, and the trust model for agent-facing products.
- Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest-user data access, and rendering trust boundaries.
- Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP).
You're Our Person If...
- You have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfaces.
- You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolution.
- You can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product work.
- You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go).
Even Better If...
- You've secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaS.
- You've done hands-on work with LLM application security, agent frameworks, or MCP.
- You've owned a security program or served as the standing security lead for a product area.
- You have bug bounty or red-team experience.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Product Security LeadSalesforce · San Francisco, CA · $173–260K/yrPosted 3w agoPosted 3w ago
Director of Product SecurityHarvey · San Francisco, CA (Hybrid) · $272–408K/yrPosted 1w agoPosted 1w ago
Principal Product Security EngineerSalesforce · San Francisco, CA · $173–314K/yrPosted 1w agoPosted 1w agoPrincipal Product Manager - Platform SecurityPagerDuty · San Francisco, CA (Hybrid) · $180–304K/yrPosted 2w agoPosted 2w ago
Product Lead, InpatientAmbience Healthcare · San Francisco, CA (Hybrid) · $203–283K/yrPosted 3w agoPosted 3w ago
You've read the whole posting — now see how you match it.