Director of Product Security

Salesforce Salesforce · Enterprise · Bellevue, WA

Salesforce is seeking a Director of Product Security to lead a mission-critical segment of their Engineering organization. The role involves defining and executing a long-term roadmap for core backend services, prioritizing security, scalability, and reliability. Responsibilities include championing "Security-by-Design", managing the vulnerability and risk lifecycle, navigating cross-functional alignment, scaling and mentoring teams, and ensuring operational excellence through automated pipelines and compliance frameworks. The ideal candidate will have extensive software engineering and leadership experience, deep product security domain knowledge, and experience securing AI models and LLM integrations within a Zero Trust framework.

What you'd actually do

  1. Define and execute a long-term roadmap for core backend services, prioritizing high availability, low latency, massive scalability, and end-to-end product security.
  2. Champion "Security-by-Design" and "Default-to-Secure" principles across the entire SDLC. Partner with centralized Information Security teams to define threat models, establish secure design standards, and embed shift-left security practices directly into engineering workflows.
  3. Oversee proactive threat modeling, static/dynamic code analysis (SAST/DAST), dependency scanning, penetration testing remediation, and bug bounty resolutions. Drive rapid incident response protocols for platform-level security vulnerabilities.
  4. Hire, develop, and retain a world-class org of 15–40+ engineers (including Managers and ICs). Build a robust Security Champions program within your org, empowering engineers to lead local threat modeling and secure code reviews.
  5. Own the full SDLC. Champion automated CI/CD pipelines, automated security gates, secrets management, zero-trust access controls, and compliance frameworks (ISO, SOC2, FedRAMP) to ensure B2C-scale services remain rock-solid and resilient.

Skills

Required

  • 12+ years of software engineering experience
  • 5 years in a significant engineering leadership role
  • Deep Product Security Domain Knowledge
  • architecting, embedding, and managing application/product security controls
  • OWASP Top 10
  • OAuth/SAML
  • cryptography standards
  • data privacy regulations
  • secure containerization/Kubernetes security
  • Experience or strategic oversight in securing AI models
  • LLM integration safety
  • data isolation
  • preventing prompt injection or data leakage within ML/AI pipelines
  • building, securing, and operating large-scale distributed systems
  • Microservices
  • Service Mesh
  • Event-driven architectures
  • strict Zero Trust framework

Nice to have

  • Manager of Managers preferred for Sr. Director

What the JD emphasized

  • end-to-end product security
  • Security-by-Design
  • Default-to-Secure
  • shift-left security practices
  • Vulnerability & Risk Lifecycle Management
  • secure design standards
  • secure code reviews
  • secure AI architecture
  • LLM integration safety
  • data isolation
  • prompt injection
  • data leakage
  • Zero Trust framework
  • compliance frameworks (ISO, SOC2, FedRAMP)