Salesforce · 6 hours ago
Senior Director, Product Security
Salesforce is the #1 AI CRM, and they are seeking a dedicated and seasoned security leader to build and lead their Product Security Advisors organization. The role involves partnering closely with the Business Information Security Officer and leading a team of technical security engineers to ensure security is embedded throughout the software lifecycle.
Agentic AIArtificial Intelligence (AI)Cloud ComputingCRMSaaSSales EnablementSoftware
Responsibilities
Build, scale, and lead the Product Security Advisors (PSA), ensuring close alignment with the broader Product Security and BISO organization
Define and drive a forward-looking security advisory strategy that supports product engineering across multiple business units
Set a clear vision for the PSA team, empowering them to influence architecture, design, deployment, and runtime security decisions
Establish measurable outcomes and reporting frameworks to track program effectiveness, risk reduction, and overall impact
Foster a culture of innovation, leveraging automation, agents, and streamlined processes to maximize efficiency and value
Implement employee success strategies that drive high performance, accountability, and retention within the PSA team
Serve as a trusted advisor to product and platform leadership, embedding with engineering teams to ensure a security-by-default approach
Partner with Product BISOs and security teams to curate aligned, risk-based priorities across business units
Influence product management and engineering to integrate risk remediation and security best practices into feature development and roadmaps
Hold stakeholders accountable for delivering remediation commitments within agreed timelines
Lead comprehensive risk assessments across architecture, design, deployment, and runtime phases
Oversee technical reviews, threat modeling, code/design reviews, and hands-on testing to uncover and mitigate risks
Analyze diverse risk signals and discovery data to prioritize security activities and inform the product security roadmap
Guide the PSA team in evaluating trade-offs, recommending optimal solutions that balance security, functionality, and business objectives
Partner with the BISO organization to align product risk management with regulatory, compliance, and customer obligations
Collaborate with CSOC, SCCT, and other security teams to incorporate lessons learned from incidents into proactive controls
Act as a security thought leader, representing Product Security Advisors in executive forums and, as needed, with external customers
Rapidly adapt to new and emerging high-risk areas, effectively persuading stakeholders to pivot priorities where required
Qualification
Required
Bachelor's degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience is required
Exceptional communication, collaboration, and interpersonal skills with the ability to effectively communicate complex technical concepts to diverse audiences, including technical and non-technical leadership
An attacker's mindset; consider abuse and attack paths as well as the defensive mindset to recommendations to prevent them
A passion around improving the security development lifecycle and delivering security guidance to engineers in a language they understand
Ability to work with data, identify trends and propose comprehensive mitigations that eradicate systemic security concerns
Experience managing or participating in an information security program and improving or proposing improvements to a secure development lifecycle
Threat modeling of security topics across infrastructure security & application security domains
Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
Exceptional writing and presentation skills
Possess the ability to communicate concisely, clearly, and intelligently to partners and executives from a variety of backgrounds, including those who are non-technical
Preferred
Experience with client side/browser security features like same origin policy, CORS, CSP, shadow DOM, Web Components, web development frameworks etc
Experience with software development in one or more languages such as: JavaScript, Java, Python, Ruby, PHP, Go, TypeScript
Some experience performing penetration testing or familiarity with the process
5+ years proven experience in the following areas in a security engineering or research role: Securing products and infrastructure from the OWASP Top 10 and/or CWE Top 25
Exploiting web and web services security vulnerabilities such as cross-site scripting, cross site request forgery, SQL injection, DoS attacks, XML/SOAP, API attacks, etc
Public Cloud security architecture in one or more of the following: Amazon Web Services, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, etc
Benefits
Time off programs
Medical
Dental
Vision
Mental health support
Paid parental leave
Life and disability insurance
401(k)
Employee stock purchasing program
Company
Salesforce
Salesforce is a cloud-based software company that provides customer relationship management software and applications.
H1B Sponsorship
Salesforce has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (1883)
2024 (2296)
2023 (1850)
2022 (2849)
2021 (2124)
2020 (1960)
Funding
Current Stage
Public CompanyTotal Funding
$65.38MKey Investors
Starboard ValueEmergence CapitalHalsey Minor
2022-10-18Post Ipo Equity
2004-06-23IPO
2003-01-01Series Unknown· $1M
Leadership Team
Recent News
2026-02-04
The Motley Fool
2026-02-03
Small Business Trends
2026-02-03
Company data provided by crunchbase