Description
Salesforce’s Security team is seeking a Network Security Senior Manager to help secure the world’s #1 CRM. As a leader of the NetSec DDoS team, you will be responsible for designing, building, and maintaining innovative security services and solutions that support the needs of our internal and external customers. You will be responsible and accountable for driving Application Security protection inside production Salesforce environments—both public cloud and first-party datacenters. This is a highly visible role that will work closely with partner teams to drive an integrated solution and respond to incidents.
RESPONSIBILITIES
Partner with other engineering teams and executives to develop short- and long-term security, product, and service strategies.
Develop vision, roadmaps, and plans with executive management to drive network security goals.
Lead research and implementation of new network security solutions and platforms for intra- and cross-data-center network flows.
Operate in an Agile development environment, including participating in daily scrums.
Collaborate with other teams to solve security problems with minimal disruption to other business functions.
Drive continuous improvement of policies, processes, procedures, and technology.
Participate in on-call coverage for critical services.
Interact with industry experts, partners, internal staff, and auditors.
Work effectively as part of a geographically distributed team.
Hire and retain top security talent, grow your team and its members, and help guide the technical direction.
Participate in problem review meetings and process improvement meetings, and actively contribute to high-risk change reviews and analysis coordination reviews.
REQUIREMENTS
Industry experience (10+ yrs of total exp)
5+ years of experience leading Network Security teams responsible for operational, project, and engineering work.
5+ years of experience in a high-availability 24/7 environment.
3+ years of experience in public cloud environments (e.g., AWS, GCP, Azure, etc.).
Management experience
3+ years of direct people management experience, with at least 6 direct reports.
M.Sc./M.Eng in Computer Science/Engineering or B.A./B.Sc. in the same disciplines with equivalent years of experience.
Network Security
Must be proficient in network architecture and design, network security, and network monitoring.
Prior experience or working knowledge of one or more of the following security technologies: firewalls, intrusion detection/prevention systems, vulnerability scanning, NAC, WAN security, DDoS.
Understanding of risks that can manifest in large-scale, complex systems.
Experience designing and operating network security technologies within public cloud environments.
Familiarity with denial-of-service attacks, mitigation strategies, and industry best practices.
Familiarity with OWASP Top 10 vulnerabilities, CWE, and related countermeasures.
Experience with log analysis and monitoring systems such as Splunk, ELK, Grafana, etc.
Security
Strong knowledge of security fundamentals, including secure transport (e.g., SSL, TLS) and identity management (e.g., certificates, PKI).
DevOps mindset
Strong ownership of owned code (test, monitor, deploy, maintain) and experience managing team delivery for global orchestration and automation of tasks.
Communication
Excellent oral and written communication skills.
Team
Ability to value team success beyond personal contributions.
Ability to work in a fast-paced environment while guiding teams through challenges.
Education
B.S. in Computer Science/Engineering or similar disciplines with equivalent years of experience.
Security certifications and/or equivalent work experience (e.g., CEH, GPYC, GPEN).
DESIRED SKILLS
Experience with multi-tiered, mission-critical systems.
Experience driving key information security, compliance, and other regulatory requirements internally and externally.
Past experience driving full-lifecycle projects.
Prior understanding of Agile/Scrum methodologies; certification is a plus.
CISM and/or CISSP certification is a plus.
A seasoned professional in corporate communications, presentation, and risk awareness.
Knowledge of ISO 27001, PCI, SOC, FISMA, and FedRAMP.
Experience designing and deploying DDoS/WAF technologies within public cloud and first-party environments.
Experience with content delivery networks such as Akamai, Cloudflare, and CloudFront.
Knowledge of Salesforce, Marketing Cloud, and/or Commerce Cloud application architecture.
Well-versed in internet fundamentals, the TCP stack, DNS and routing, and communication protocols such as HTTP or TLS.
