Lead Security Consultant - Professional Services Security Assurance (PSSA)

Airkit
Airkit

IT, Sales & Business Development

San Francisco, CA, USA

Posted on Aug 7, 2026

Description

About the Team

We are building a brand new Professional Services Security Assurance (PSSA) team — a true 0 to 1 opportunity. This team sits within the Security Practice, part of the broader Professional Services organization. Our mission is to empower the Professional Services organization to deliver secure implementations and protect customer data at scale.
We focus on securing the configurations, integrations, and implementations delivered to our customers. As a founding, hands-on technical member of the Security Assurance team within our Security Practice, you will deliver direct security engagements to our customers, ensuring every deployment is secure by design — and shaping the strategic foundation of our practice.

Role Overview

As a hands-on technical expert, you will act as a force multiplier for our PSSA organization. Your primary focus is the delivery of high-impact security engagements directly to our customers, translating complex technical risks into actionable security postures.

What You'll Do

  • Lead customer engagements by performing in-depth, high-quality security assessments of web, mobile, API, cloud, and AI-enabled applications — including architecture and design reviews, threat modeling, secure code reviews, and penetration testing.

  • Conduct threat modeling exercises to identify potential attack vectors, evaluate business risk, and recommend security controls that effectively balance security, usability, and business objectives.

  • Develop comprehensive security assessment reports that clearly communicate findings, risk ratings, and actionable remediation recommendations to both technical and executive stakeholders.

  • Serve as a trusted security advisor to customers by providing practical remediation guidance, security best practices, and recommendations that improve the overall security posture of their applications and services.

  • Collaborate closely with the professional services org to integrate security throughout the software development lifecycle, from design through deployment.

  • Develop and enhance assessment methodologies, automation, and security tooling to improve assessment quality, consistency, and scalability across customer engagements.

  • Define and contribute to technical security standards, reference architectures, and secure development guidelines in partnership with internal teams and customers.

  • Research emerging technologies, evolving attack techniques, and security vulnerabilities to continuously improve assessment methodologies and provide proactive security recommendations.

  • Build strong customer relationships through effective communication, technical leadership, and consultative engagement throughout the assessment lifecycle.

You're Our Person If...

Required Experience

  • Senior: 5+ years of experience in Application Security, Product Security, or Security Consulting

  • Lead: 8+ years of experience in Application Security, Product Security, or Security Consulting

  • Hands-on experience performing application security assessments, including architecture and design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews.

  • Strong understanding of common application security vulnerabilities and secure development practices, including the OWASP Top 10, API Security Top 10, and common attack techniques.

  • Experience assessing modern application architectures, including web applications, APIs, microservices, containers, cloud-native environments, and AI-enabled applications.

  • Experience communicating security findings, risk, and remediation guidance to technical and executive stakeholders.

  • Strong customer-facing consulting skills with the ability to build trusted relationships and influence security outcomes across diverse organizations.

  • Excellent analytical, problem-solving, collaboration, written, and verbal communication skills.

  • Proficiency in one or more programming or scripting languages such as Java, Python, JavaScript/TypeScript, Go, or C#.

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related technical field — or equivalent practical experience.

Even Better If You Have...

  • Experience assessing AI applications and agentic systems.

  • Experience developing security automation, reusable assessment frameworks, or security tooling to improve assessment quality and scale.

  • Familiarity with industry security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, and MITRE ATT&CK.

  • Experience defining and communicating prioritized remediation plans and partnering with engineering teams to drive security improvements.

  • Experience mentoring security consultants or leading technical customer engagements.

Why Join Us

This is a founding role — a rare chance to build something from the ground up within an established, high-scale Professional Services organization. You'll set the tone for how we deliver security, mentor future team members, and directly shape the methodologies and culture of the PSSA practice.

Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.