Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Product Security Principal image - Rise Careers
Job details

Product Security Principal

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category... Product Job Details About Salesforce We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place. About Our Team The Reference Designs, Security Controls, and Architecture (REDSCAR) Team is the Built-In Security team that focuses on reducing security risk at scale in Salesforce products and infrastructure while also enabling developers enhance deployment times by providing building blocks and a secure foundation that integrate security by default. This is accomplished through centralized security requirements, architectural patterns, secure-by-default infrastructure and application building blocks, pipeline-embedded and runtime guardrails, and robust detection mechanisms to identify security risks. While the REDSCAR team focuses on both application security and infrastructure, this position will play a key role specifically in the application security domain. If you are passionate about the field of application security and have a proven track record of successfully solving complex application security challenges in your previous roles, then we are looking for you. Responsibilities As a principal security engineer for Application Security, you will play a crucial role in ensuring the security and integrity of our software products. You will lead efforts to strengthen our application security posture, reduce application security vulnerabilities at scale, contribute to development of high confidence SAST rules and defensive libraries. In addition, part of the responsibilities will involve actively contributing to the process of bringing our security products to General Availability, ensuring their readiness and effectiveness in meeting security requirements and business needs. This role will also require collaborative engagement with cross-functional teams, as you play a pivotal role in seamlessly integrating security measures into the development process. Your contribution will be instrumental in strategically shifting security practices to an earlier stage, ensuring that security becomes an inherent part of our development culture. Minimum Qualifications • Bachelor's Degree or equivalent work experience required, preferred Master in engineering, computer science, or a related technical field • 10+ years experience in security field (Pen-Tester, Blue Team, Threat Modeling, Security Researcher, etc) • Strong understanding of application security controls and their implementation at scale (e.g. SAST, DAST, template scanning, security libraries, 3rd part libraries) • Ability to see the big picture and build out concise, comprehensive, yet realistic project plans to solve complex problems • Ability to write scripts and automating tasks that require processing a number of files, preferably in Python or Shell • Ability to work cross-functionally, context switch, learn fast, and communicate well • Proficiency in data analysis to inform data-driven decision-making including decisions on false positives, false negatives, and true positives Required Qualifications • Understanding of OWASP Top 10 and secure coding guidelines • Ability to identify and mitigate security vulnerabilities and threats. Experience developing mitigations to OWASP Top 10 Security vulnerabilities and/or WASC-25 Security Vulnerabilities • Proficiency in at least one core (Java, C#, Python, Go, etc.) and one scripting (Shell, Python, etc) language. • Comfortable learning various code review pattern across different languages. Language proficiency is not a must, but understanding language agnostic syntax quickly and finding vulnerable patterns is necessary • Ability to translate from compliance and security requirements through product requirements and implement them in automation • Knowledge of integrating security into DevOps practices, enabling the shift of security left in the development lifecycle • Effective communication and collaboration skills to work seamlessly with cross-functional teams • Ability to manage your own projects Preferred Qualifications • Passionate for improving security, systems, and processes • Experience in leveraging prompt engineering methodologies to enhance application security • Development experience in AWS (experience with Azure, Alibaba, GCP is a plus) • CISSP certification or other security certifications related to Application Security (e.g. OSWE, GWAPT, CSSLP, CEH) Accommodations If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form. Posting Statement At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com. Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce. Salesforce welcomes all. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. For Washington-based roles, the base salary hiring range for this position is $204,400 to $296,400. For California-based roles, the base salary hiring range for this position is $223,000 to $323,400. Compensation offered will be determined by factors such as location, level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, benefits. More details about our company benefits can be found at the following link: https://www.salesforcebenefits.com
Salesforce Glassdoor Company Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Salesforce DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Salesforce
Salesforce CEO photo
Marc Benioff
Approve of CEO

Salesforce was founded with a mission to transform business operations and make a positive global impact. It is a cloud-based company providing customer relationship management (CRM) software and applications.

148 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Future MakerBadge Global CitizenBadge InnovatorBadge Future UnicornBadge Rapid Growth
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Feedback Forward
Take Risks
Collaboration over Competition
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Employee Resource Groups
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
June 10, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
Other jobs
Company
Doppel Remote No location specified
Posted 6 months ago
Company
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Employee Resource Groups
Company
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Employee Resource Groups