Product Security Lead

Salesforce

Bellevue (KY)

On-site

USD 150,000 - 210,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical Care
Life Insurance
Retirement Savings
Employee Assistance Programs
13 paid holidays / year

Job summary

Salesforce is seeking a technical security lead for the user-facing application and experience layers of our platform. You will own security assurance, drive threat modeling and secure-by-default patterns across web and UI frameworks, and review code in JavaScript/TypeScript and Java.

You will shape license-to-operate trust boundaries, own AI and agentic risk, and collaborate with product and engineering across multi-release programs while serving as a trusted security voice within a top-tier

Qualifications

  • Track record of authoring security standards and leading cross-team security programs.
  • Fluent in reviewing JavaScript/TypeScript and Java codebases for security issues.
  • Experience with threat-modeling across large web/UI/data-access environments.
  • Knowledge of AI/LLM security and agent frameworks is a plus.
  • Familiarity with guest-user data access security and rendering trust boundaries.

Responsibilities

  • Lead security assurance for UI/experience layers of the platform across web and UI frameworks.
  • Drive threat modeling, security design reviews, and targeted code reviews (JS/TS, Java).
  • Shape secure-by-default patterns upstream and push secure patterns into frameworks and SDKs.
  • Own AI and agentic risk; design gates for high-risk actions and enforce least-privilege.
  • Serve as security voice in a top-tier Engineering organization delivering multi-release programs.

Skills

Threat modeling
Security reviews
JS/TS security
Cross-team leadership
Guest-user security
Web security
AI security
Least privilege

Job description


  • Salesforce’s Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on

  • We are hands-on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world’s #1 CRM platform secure

  • This role serves as the technical security lead for the user-facing application and experience layers of the platform, including front-end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences

  • It also covers fast-growing AI agent-driven experiences and web data-access surfaces that render across our own surfaces, third-party channels, and external agentic clients

  • You’ll set the security assurance bar across these areas

  • You’ll shape how controls are designed and drive secure-by-default patterns upstream

  • You’ll serve as a trusted security voice to a top-tier Engineering organization delivering multi-release, cross-team programs, at a time when this layer’s trust model is being redefined

  • Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them

  • Serve as the standing security lead for multi-quarter, multi-team programs such as the expansion of guest-user data access, first-party experiences rendering into surfaces we don’t control, and the trust model for agent-facing products

  • Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest-user data access, and rendering trust boundaries

  • Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP)


Benefits


  • Medical Care

  • Life Insurance

  • Retirement Savings

  • Employee Assistance Programs

  • With 9 standard holidays and four floating holidays, you get a total 13 paid days off each year


You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go)You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolutionYou can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product workYou have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfacesYou’ve secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaSYou’ve done hands-on work with LLM application security, agent frameworks, or MCPYou’ve owned a security program or served as the standing security lead for a product areaYou have bug bounty or red-team experience

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Lead: UI/AI Security & Trust
Product Security Lead: UI/AI Security & Trust

Salesforce • Bellevue (KY)

On-site
USD 150,000 - 210,000
Medical Care
Life Insurance
Retirement Savings
+2
Product Security Lead: AI & UI Trust
Product Security Lead: AI & UI Trust

Salesforce • San Francisco (CA)

On-site
USD 173,000 - 260,000
Senior Product Security Lead - UI & AI Risk
Senior Product Security Lead - UI & AI Risk

salesforce.com, inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

Salesforce • San Francisco (CA)

On-site
USD 173,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New York (NY)

On-site
USD 180,000 - 230,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • San Francisco (CA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead — UI & AI Trust Architect
Product Security Lead — UI & AI Trust Architect

Salesforce • Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead — UI & AI Trust Architect
Product Security Lead — UI & AI Trust Architect

100 Salesforce, Inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Time off programs
Medical
Dental
+4
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

GoodLeap • United States

On-site
USD 146,000 - 169,000
Bonus eligible