- Salesforce’s Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on
- We are hands-on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world’s #1 CRM platform secure
- This role serves as the technical security lead for the user-facing application and experience layers of the platform, including front-end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences
- It also covers fast-growing AI agent-driven experiences and web data-access surfaces that render across our own surfaces, third-party channels, and external agentic clients
- You’ll set the security assurance bar across these areas
- You’ll shape how controls are designed and drive secure-by-default patterns upstream
- You’ll serve as a trusted security voice to a top-tier Engineering organization delivering multi-release, cross-team programs, at a time when this layer’s trust model is being redefined
- Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them
- Serve as the standing security lead for multi-quarter, multi-team programs such as the expansion of guest-user data access, first-party experiences rendering into surfaces we don’t control, and the trust model for agent-facing products
- Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest-user data access, and rendering trust boundaries
- Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP)
Benefits
- Medical Care
- Life Insurance
- Retirement Savings
- Employee Assistance Programs
- With 9 standard holidays and four floating holidays, you get a total 13 paid days off each year
You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go)You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolutionYou can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product workYou have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfacesYou’ve secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaSYou’ve done hands-on work with LLM application security, agent frameworks, or MCPYou’ve owned a security program or served as the standing security lead for a product areaYou have bug bounty or red-team experience