Product Security Lead
What you'll need to apply
Fields this application requires
Company-specific questions
- Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
- Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
- I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
- Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
The Experience
Salesforce's Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on. We are hands-on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world's #1 CRM platform secure.
This role serves as the technical security lead for the user-facing application and experience layers of the platform, including front-end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences. It also covers fast-growing AI agent-driven experiences and web data-access surfaces that render across our own surfaces, third-party channels, and external agentic clients.
You'll set the security assurance bar across these areas. You'll shape how controls are designed and drive secure-by-default patterns upstream. You'll serve as a trusted security voice to a top-tier Engineering organization delivering multi-release, cross-team programs, at a time when this layer's trust model is being redefined.
What You'll Actually Be Doing
- Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them.
- Serve as the standing security lead for multi-quarter, multi-team programs such as the expansion of guest-user data access, first-party experiences rendering into surfaces we don't control, and the trust model for agent-facing products.
- Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest-user data access, and rendering trust boundaries.
- Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP).
You're Our Person If...
- You have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfaces.
- You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolution.
- You can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product work.
- You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go).
Even Better If...
- You've secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaS.
- You've done hands-on work with LLM application security, agent frameworks, or MCP.
- You've owned a security program or served as the standing security lead for a product area.
- You have bug bounty or red-team experience.