Security Problem Management Principal

Salesforce

Virginia (IL)

On-site

USD 140,000 - 180,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Salesforce is seeking a Security Problem Manager to lead end-to-end problem management for security incidents, vulnerabilities, and control failures. The role collaborates across Security, Engineering, Infrastructure, Product, and Risk to drive root-cause analyses and durable remediation.

The ideal candidate has 10+ years in cybersecurity or related fields, strong program-management skills, and the ability to translate technical risk into business actions. U.S.

Qualifications

  • 10+ years of experience in cybersecurity, security operations, incident response, problem management, risk management, reliability engineering, or a related discipline.
  • Strong understanding of security incidents, vulnerabilities, controls, threat scenarios, and technical risk.
  • Demonstrated experience facilitating root-cause analyses or post-incident reviews.
  • Ability to translate complex technical findings into clear business risks, decisions, and actions.
  • Strong program-management skills, including ownership tracking, prioritization, dependency management, and executive communication.
  • Ability to work effectively across engineering, operations, product, legal, compliance, and leadership teams.
  • Excellent written and verbal communication skills.
  • Sound judgment and the ability to challenge incomplete analyses or insufficient remediation constructively.

Responsibilities

  • Own the end-to-end security problem management lifecycle, from problem identification through closure and effectiveness validation.
  • Identify recurring incidents, control failures, vulnerabilities, and operational trends that require deeper investigation.
  • Facilitate root-cause analyses and post-incident reviews using structured methods such as five whys, fault-tree analysis, and causal analysis.
  • Create and maintain high-quality problem records containing impact, contributing factors, root cause, risk, corrective actions, owners, and deadlines.
  • Distinguish root causes from symptoms and ensure remediation addresses systemic weaknesses.
  • Partner with incident response teams to transition significant incidents into formal problem investigations.
  • Track corrective and preventive actions to completion, escalating overdue or blocked work when necessary.
  • Validate that remediation is effective and has not merely transferred risk to another system or team.
  • Analyze incident, vulnerability, and control-failure data to identify emerging patterns and systemic risks.
  • Develop metrics and reporting for senior leadership, including recurrence rates, remediation aging, overdue actions, and risk reduction.
  • Improve problem-management processes, standards, templates, tooling, and governance.
  • Promote blameless reviews that encourage transparency, learning, and sustainable engineering improvements.
  • Maintain alignment with security policies, risk-management requirements, and relevant regulatory obligations.

Skills

Cybersecurity
Incident response
Problem management
Program management
Executive communication
Cross-functional collaboration
Risk assessment

Tools

NIST CSF
NIST 800-61
ISO 27001
ITIL
PMP

Job description

Job Category

Enterprise Technology & Infrastructure

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience

The Security Problem Management Principle leads the identification, analysis, and resolution of systemic security problems. This role works across Security, Engineering, Infrastructure, Product, and Risk teams to determine root causes, prevent recurrence, and ensure corrective actions are completed.

The ideal candidate combines security knowledge, structured problem-solving, program management, and the ability to influence technical and business stakeholders. They promote a blameless learning culture while maintaining clear ownership and accountability for risk reduction.

What You'll Actually Be Doing
  • Own the end-to-end security problem management lifecycle, from problem identification through closure and effectiveness validation.
  • Identify recurring incidents, control failures, vulnerabilities, and operational trends that require deeper investigation.
  • Facilitate root-cause analyses and post-incident reviews using structured methods such as five whys, fault-tree analysis, and causal analysis.
  • Create and maintain high-quality problem records containing impact, contributing factors, root cause, risk, corrective actions, owners, and deadlines.
  • Distinguish root causes from symptoms and ensure remediation addresses systemic weaknesses.
  • Partner with incident response teams to transition significant incidents into formal problem investigations.
  • Track corrective and preventive actions to completion, escalating overdue or blocked work when necessary.
  • Validate that remediation is effective and has not merely transferred risk to another system or team.
  • Analyze incident, vulnerability, and control-failure data to identify emerging patterns and systemic risks.
  • Develop metrics and reporting for senior leadership, including recurrence rates, remediation aging, overdue actions, and risk reduction.
  • Improve problem-management processes, standards, templates, tooling, and governance.
  • Promote blameless reviews that encourage transparency, learning, and sustainable engineering improvements.
  • Maintain alignment with security policies, risk-management requirements, and relevant regulatory obligations.

This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role.

You're Our Person If You Have:
  • 10+ years of experience in cybersecurity, security operations, incident response, problem management, risk management, reliability engineering, or a related discipline.
  • Strong understanding of security incidents, vulnerabilities, controls, threat scenarios, and technical risk.
  • Demonstrated experience facilitating root-cause analyses or post-incident reviews.
  • Ability to translate complex technical findings into clear business risks, decisions, and actions.
  • Strong program-management skills, including ownership tracking, prioritization, dependency management, and executive communication.
  • Ability to work effectively across engineering, operations, product, legal, compliance, and leadership teams.
  • Excellent written and verbal communication skills.
  • Sound judgment and the ability to challenge incomplete analyses or insufficient remediation constructively.
Even Better If You Have:
  • Experience in a large-scale cloud, SaaS, or enterprise technology environment.
  • Familiarity with security operations centers, incident-command practices, vulnerability management, and threat intelligence.
  • Knowledge of frameworks such as NIST CSF, NIST 800-61, ISO 27001, ITIL, or similar standards.
  • Experience with operational data analysis, dashboards, case-management systems, or work-tracking tools.
  • Relevant certifications such as CISSP, CISM, CRISC, GIAC, ITIL, or PMP.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Unleash Your Potential

When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Problem Management Principal
Security Problem Management Principal

Relha LLC • Virginia (IL), Northern (KY)

Hybrid
USD 197,000 - 314,000
Security Problem Management Principal
Security Problem Management Principal

Salesforce, Inc. • Virginia (IL), Northern (KY)

Hybrid
USD 197,000 - 314,000
Medical
Dental
Vision
+5
Security Problem Management Principal
Security Problem Management Principal

salesforce.com, inc. • McLean (VA)

On-site
USD 197,000 - 314,000
Security Problem Management Principal
Security Problem Management Principal

Salesforce • McLean (VA)

On-site
USD 197,000 - 314,000
Security Problem Management Principal
Security Problem Management Principal

Socket.dev • McLean (VA)

On-site
USD 197,000 - 314,000
BISO - Product Security (Multiple Levels)
BISO - Product Security (Multiple Levels)

Salesforce • United States

On-site
USD 150,000 - 210,000
Lead Vulnerability Commander
Lead Vulnerability Commander

salesforce.com, inc. • Virginia (MN)

On-site
USD 173,000 - 260,000
Lead Vulnerability Commander
Lead Vulnerability Commander

salesforce.com, inc. • Washington

On-site
USD 173,000 - 260,000
Lead Vulnerability Commander
Lead Vulnerability Commander

Salesforce • Washington

On-site
USD 173,000 - 260,000
Senior Technical Program Manager, Security
Senior Technical Program Manager, Security

Salesforce • Palo Alto (CA)

On-site
USD 150,000 - 227,000