Senior Manager, Information Security & Compliance

Salesforce Salesforce · Enterprise · Mumbai, India

This role is for a Senior Manager of Information Security & Compliance at Salesforce, focusing on acting as a customer-facing security advisor. The individual will manage security, risk, and compliance assessments, engage with executive stakeholders, and provide thought leadership on Salesforce's security posture. Responsibilities include collaborating with internal teams, supporting incident response, advising on contractual and compliance matters, enabling sales teams, influencing the product roadmap, and developing security content. The role requires experience in information security, GRC, and a strong understanding of the Indian regulatory environment, particularly for public sector procurement and SaaS empanelment.

What you'd actually do

  1. Serve as a trusted security advisor by developing a deep understanding of customer business objectives, risk posture, and strategic challenges, ensuring alignment between customer requirements and Salesforce security capabilities.
  2. Act as the primary security representative for customers, prospects, and internal stakeholders, leading responses to security, risk, and compliance assessments, questionnaires, and due diligence requests.
  3. Build and strengthen customer trust through executive-level security discussions, briefings, and strategic engagements with customers, prospects, and key decision-makers.
  4. Serve as a Subject Matter Expert (SME) on Salesforce's security, privacy, compliance, reliability, and architectural capabilities, effectively articulating and advocating Salesforce's trust posture in customer-facing interactions.
  5. Partner closely with Product Management, Engineering, Legal, Privacy, and Security teams to ensure customer-facing security messaging, documentation, and responses accurately reflect current capabilities and best practices.

Skills

Required

  • Information security
  • Security architecture
  • Governance, Risk, and Compliance (GRC)
  • Customer-facing roles
  • Regulatory environment in India
  • Public sector procurement
  • Government e-Marketplace (GeM)
  • MeitY SaaS empanelment
  • Penetration testing
  • Vulnerability assessment
  • Metasploit
  • Burp Suite
  • Nmap
  • Wireshark
  • Public sector entities support
  • Indian financial services industry experience

Nice to have

  • Salesforce products and services expertise
  • Public policy and regulatory affairs engagement

What the JD emphasized

  • Good understanding of the regulatory environment in India as it pertains to public sector procurement practices, Government e-Marketplace (GeM), and Ministry of Electronics and Information Technology (MeitY) SaaS empanelment requirements.
  • Comprehensive understanding of the Indian public sector procurement landscape, including Government e-Marketplace (GeM) protocols, MeitY SaaS empanelment criteria, and standard RFI/RFP frameworks.