Information Security Senior

Salesforce Salesforce · Enterprise · Washington, VA · Remote

Salesforce is seeking a Senior Information Security professional for their Government Cloud Division. This role involves driving security initiatives, supporting change management with federal authorization bodies, managing continuous monitoring, incident response, and advising on security requirements. The candidate will work with various stakeholders, including business, legal, and technical teams, and must have experience with government cloud environments and security frameworks like FedRAMP. Experience with operationalized AI automation strategies and leveraging AI for daily tasks is preferred.

What you'd actually do

  1. Drive existing or newly identified initiatives between stakeholder organizations creating synergies and reducing risk of non-compliance with internal or external requirements
  2. Support change management activities with federal authorization bodies
  3. Support multiple security pillars within Salesforce Government Cloud Division including but not limited to, continuous monitoring activities, advisory, incident response, adoption of AI, and security documentation
  4. Consult with business or security stakeholders on information security requirements and applicability to their business processes, products, or services
  5. Create and maintain relationships with key business, legal, Employee Success, Internal Audit, technical/engineering stakeholders, and other organizations throughout the company who provide expertise in security requirements and solution management

Skills

Required

  • Minimum 8 years of experience in information security, cybersecurity, accreditation, and other security related areas
  • Experience working with Government Cloud environments such as AWS, Azure, GCP (SaaS, IaaS, PaaS etc)
  • Experience in security related analysis, creating metrics and dashboards and summarizing large data sets
  • Ability to work with both business and technical areas and translate between the two areas
  • Skilled at building rapport and establishing partnerships
  • Excellent verbal and written communication skills and ability to communicate results to multiple levels of management
  • Knowledge security frameworks (FedRAMP20x, DoD SRG)
  • Demonstrated desire to learn new skills and innovate
  • Agile, proactive, comfortable working with ambiguous specifications and can prioritize quickly and effectively
  • Excellent interpersonal, relationship, and organizational skills
  • Excellent analytical and process development skills
  • Detail oriented with an eye for quality
  • Drive improvements in existing processes and develop new innovative and efficient solutions
  • Ability to work effectively with a wide range of individuals including developers, systems administrators, executives, customers, regulators, auditors, etc.
  • Experience building productive relationships with Technical Operations, Security Operations, Incident Response, Technical Compliance, Engineering, and other stakeholders
  • Experience working directly with Authorizing Officials in Federal Civilian agencies, including the Department of Defense (DoD), specifically the DISA Cloud Assessment Division.
  • Proven experience in Compliance Engineering

Nice to have

  • Operationalized AI automation strategies
  • CISSP, CISA, CISM, AWS or similar certifications a plus
  • Coding or scripting experience
  • Experience leveraging AI to help facilitate day-to-day tasks.
  • Understanding of FedRAMP 20x standards and requirements.
  • Compliance engineering experience (e.g., developing tools, processes or requirements to facilitate compliance related work).

What the JD emphasized

  • U.S. citizen
  • operating on U.S. Soil
  • does not hold dual citizenship
  • FedRAMP
  • DoD SRG
  • Federal Civilian agencies
  • Department of Defense (DoD)
  • DISA Cloud Assessment Division