Product Security Lead

Salesforce

Washington

On-site

USD 160,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Salesforce's Platform Security team seeks a hands‑on security engineer to lead the security assurance for the user‑facing experience and UI layer of the platform. You will drive threat modeling, security design reviews, and code reviews across web frameworks and runtimes, focusing on front‑end and agent‑driven surfaces.

You will shape secure patterns, oversee multi‑quarter programs, and own AI/agent risk, including MCP and guest‑user data access, while collaborating with top‑tier engineering

Qualifications

  • Deep expertise in web/application security and modern UI frameworks.
  • Threat-modeling experience across web/UI/data environments.
  • Ability to review JavaScript/TypeScript and another language (Java, Python, or Go).

Responsibilities

  • Lead security assurance for the experience and UI layer, including threat modeling and design reviews.
  • Coordinate with multi‑team programs on guest‑user data access and trust models.
  • Publish secure patterns and standards for web/UI security and data access.

Skills

Web/application security
Security of UI frameworks
Threat modeling
JavaScript/TypeScript
Java

Job description

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience

Salesforce's Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on. We are hands‑on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world's #1 CRM platform secure. This role serves as the technical security lead for the user‑facing application and experience layers of the platform, including front‑end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences. It also covers fast‑growing AI agent‑driven experiences and web data‑access surfaces that render across our own surfaces, third‑party channels, and external agentic clients. You'll set the security assurance bar across these areas. You'll shape how controls are designed and drive secure‑by‑default patterns upstream. You'll serve as a trusted security voice to a top‑tier Engineering organization delivering multi‑release, cross‑team programs, at a time when this layer's trust model is being redefined.

What You'll Actually Be Doing

Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest‑user‑exposed data‑access APIs beneath them.

Serve as the standing security lead for multi‑quarter, multi‑team programs such as the expansion of guest‑user data access, first‑party experiences rendering into surfaces we don't control, and the trust model for agent‑facing products.

Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest‑user data access, and rendering trust boundaries.

Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human‑in‑the‑loop gates for high‑risk actions; and define least‑privilege scoping, audit logging, and short‑lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP).

You're Our Person If...

You have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data‑access APIs, with hands‑on experience finding and eliminating web weakness classes and securing guest‑user or unauthenticated surfaces.

You have threat‑modeling experience across complex web, UI, or data‑access environments, driven to resolution.

You can reason about AI/large language model (LLM) or agentic risk - prompt injection, tool/agent abuse, or MCP/connector security - applied to real product work.

You have a track record of authoring security standards and leading cross‑team, multi‑release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go).

Even Better If...

You've secured UI frameworks, web runtimes, GraphQL/data‑access APIs, or rendering frameworks at scale, ideally for a large‑scale multi‑tenant SaaS.

You've done hands‑on work with LLM application security, agent frameworks, or MCP.

You've owned a security program or served as the standing security lead for a product area.

You have bug bounty or red‑team experience.

Unleash Your PotentialWhen you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Please note that Salesforce use

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Lead
Product Security Lead

Socket.dev • California (MO), Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • San Francisco (CA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

Salesforce • San Francisco (CA)

On-site
USD 173,000 - 260,000
Product Security Senior
Product Security Senior

Salesforce • Washington

On-site
USD 150,000 - 210,000
Sr. Product Manager, Enterprise Security Technology
Sr. Product Manager, Enterprise Security Technology

Salesforce • Washington

On-site
USD 140,000 - 190,000
Product Security Senior
Product Security Senior

Salesforce, Inc. • Northern (KY)

Hybrid
USD 149,000 - 224,000
Time off programs
Medical
Dental
+6
Product Security Senior
Product Security Senior

salesforce.com, inc. • San Francisco (CA)

On-site
USD 149,000 - 224,000
Product Security Senior
Product Security Senior

salesforce.com, inc. • Bellevue (WA)

On-site
USD 149,000 - 246,000
Security GRC Senior Analyst
Security GRC Senior Analyst

Salesforce, Inc. • United States

On-site
USD 117,000 - 177,000