An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Salesforce seeks a Senior BISO to lead product security programs across SaaS and on‑prem services. You will drive risk reduction, engage executive stakeholders, and guide security initiatives across business units with deep technical expertise.
With 10+ years in information security and 5–10 years in leadership, you bring cloud, network, and application security strengths, plus familiarity with SOX/NIST/ISO controls and third‑party risk management. CISSP/CISM valuable.
This pivotal role for a BISO within our product security organization requires a blend of real-world experience and deep knowledge in software security, including application security, cloud security, secure coding practices, and security architecture, especially across Software as a Service (SaaS) and On-premise servicesThe ideal candidate will have a proven track record of excellence in security delivery and the ability to work with a broad set of executive stakeholders across business units and security teams to drive security initiatives and improve risk postureDeep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third-party risk management frameworksAbility to thrive in a dynamic, fast-paced environment, staying ahead of emerging threats and adapting strategies to evolving business needsStrong stakeholder management and collaboration skills to work with cross-functional teams and ability to influence decision-making without direct authorityStrong understanding of security and compliance frameworks (e.g., SOX, NIST CSF, ISO 27001/2, CIS Controls)A related technical degree requiredDemonstrated ability to work independently, take ownership of security initiatives, and drive results with minimal supervisionFamiliarity with security tools such as SIEM: Splunk specifically, vulnerability scanners (e.g., Qualys, Nessus), or IAM solutions (e.g., Okta, SailPoint)Customer-focused: You know how to balance your “get it done” attitude with diplomacy to be able to work effectively across different teams and at all levelsStrong executive presence and immaculate ability to articulate technical security concepts in a business/risk context10+ years of experience in information security, with at least 5-10 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third-party integrationsExcellent communication skills to translate complex security concepts into business-friendly languageProven ability to prioritize initiatives utilizing risk data from multiple input sources, while staying aligned with the bigger pictureDeep understanding of securing AI solutionsPrior experience as BISO or equivalent is desirableAbility to cultivate strong working relationships with customer teams and internal security teams, including those in international locationsStrong willingness to challenge status quo and drive continuous improvement through change and new ideasCertifications like CISM or CISSP highly desiredTrack record of auditing related or consulting experience, high tech industry a plus