Description
The Experience:
As a Director of Product Security you will lead a mission-critical segment of Salesforce's Engineering organization. You will be responsible for the architectural integrity, scalability, zero-trust security architecture, and operational reliability of distributed services that power millions of customer interactions every second.
Strategic Technical Leadership: Define and execute a long-term roadmap for core backend services, prioritizing high availability, low latency, massive scalability, and end-to-end product security.
Product Security & Trust Culture: Champion "Security-by-Design" and "Default-to-Secure" principles across the entire SDLC. Partner with centralized Information Security teams to define threat models, establish secure design standards, and embed shift-left security practices directly into engineering workflows.
Vulnerability & Risk Lifecycle Management: Oversee proactive threat modeling, static/dynamic code analysis (SAST/DAST), dependency scanning, penetration testing remediation, and bug bounty resolutions. Drive rapid incident response protocols for platform-level security vulnerabilities.
Navigate the Salesforce Matrix: Drive alignment across cross-functional "Clouds" (Sales, Service, Marketing, etc.). Collaborate with dotted-line stakeholders, Security Champions, and Architecture Councils to ensure security policies, encryption protocols, and enterprise identity standards integrate seamlessly across the ecosystem.
Team Scaling & Mentorship: Hire, develop, and retain a world-class org of 15–40+ engineers (including Managers and ICs). Build a robust Security Champions program within your org, empowering engineers to lead local threat modeling and secure code reviews.
Architectural Diplomacy: Act as a bridge between executive leadership, Chief Information Security Officer (CISO) stakeholders, and deep-tech engineering teams. Translate complex technical vulnerabilities, compliance mandates, and architectural risks into clear executive business impact.
Operational Excellence: Own the full SDLC. Champion automated CI/CD pipelines, automated security gates, secrets management, zero-trust access controls, and compliance frameworks (ISO, SOC2, FedRAMP) to ensure B2C-scale services remain rock-solid and resilient.
Hands-on Technical Acumen: Participate in high-level design reviews, security architecture audits, and bottleneck troubleshooting across modern language environments (Java, Golang, Python).
You're Our Person If:
Engineering Pedigree: 12+ years of software engineering experience, with at least 5 years in a significant engineering leadership role (Manager of Managers preferred for Sr. Director).
Deep Product Security Domain Knowledge: Proven track record of architecting, embedding, and managing application/product security controls (OWASP Top 10, OAuth/SAML, cryptography standards, data privacy regulations, secure containerization/Kubernetes security).
Secure AI Architecture: Experience or strategic oversight in securing AI models, LLM integration safety, data isolation, and preventing prompt injection or data leakage within ML/AI pipelines.
Distributed Systems & Zero Trust: Proven experience building, securing, and operating large-scale distributed systems (Microservices, Service Mesh, Event-driven architectures) under a strict Zero Trust framework.
In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.
