Cloud Security Architect

Salesforce.com, Inc.
New York, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 218K

Job location

New York, United States of America

Tech stack

API
Business Logic
Cloud Computing
Cloud Computing Security
Cloud Engineering
Computer Security
Computer Networks
Continuous Integration
DevOps
Identity and Access Management
Intrusion Detection Systems
Secure Coding
Software Vulnerability Management
Web Applications
Data Logging
Google Cloud Platform
Software Security
Multi-Cloud
Infrastructure as Code (IaC)
Kubernetes
CIS Benchmarks
Terraform
Serverless Computing

Job description

A key leader, the Cloud Security Architect will drive the security related efforts related to design, implementation, and maintenance of secure cloud environments leveraging cloud-native services and security tooling for proactive risk reduction on GCP and other environments. This role requires deep expertise in public cloud security principles, best practices, and cutting-edge technologies to define security baselines, enforce policies, and embed security into public cloud architectures. You aren't just auditing checklists; you are building the blueprints. This role bridges the gap between Product Security (the "what" we build) and Cloud Infrastructure (the "how" we run it). You will drive the adoption of "Security by Design," ensuring that our GCP-heavy environment is automated, resilient, and proactive against modern threats. Cloud Security:

  • Security Baselines: Define and enforce comprehensive security policies and standards across multi-cloud environments, with a primary focus on GCP.
  • Native Tooling: Architect and implement Google Cloud Native Security Services (Chronicle, Cloud Armor, Cloud IDS, KMS, and Secret Manager).
  • Identity & Governance: Design sophisticated IAM structures and organizational hierarchies to ensure least-privileged access at scale.
  • Detection & Response: Partner with the CSOC to integrate logging and monitoring telemetry into actionable security posture management.

Product Security:

  • Threat Modeling: Lead deep-dive threat modeling sessions for new products and features, identifying architectural flaws before a single line of code is deployed.
  • Full-Stack Reviews: Scope and perform security reviews of web applications, APIs, and platform architectures.
  • Vulnerability Management: Triage vulnerabilities from internal testing, bug bounties, and public disclosures, providing engineers with researched remediation guidance.
  • Advocacy: Write and promote secure development practices, acting as the primary SME for engineering teams to consult on "secure-by-default" coding.

Modern Cloud Architecture:

  • Infrastructure as Code (IaC): Use Terraform to bake security into the CI/CD pipeline, ensuring every resource is provisioned with hardened configurations.
  • Container Orchestration: Secure our Kubernetes (GKE) footprint by implementing pod security standards, network policies, and container image scanning.
  • Security Parity: Ensure consistent security controls across diverse environments, minimizing "configuration drift" through automated drift detection.
  • Innovation: Continuously evaluate emerging technologies to replace manual security routines with automated, scalable solutions.

Requirements

  • 15+ Years of progressive experience in security architecture, with at least 5 years specifically focused on cloud-native environments.
  • GCP Mastery: Deep, demonstrable experience with Google Cloud Platform and its native security suite.
  • Automation Mindset: Proven ability to write and review Terraform and manage security within Kubernetes clusters.
  • Security Frameworks: Expert knowledge of NIST, CIS Benchmarks, and ISO 27001, and how to map them to technical cloud controls.

Leadership:

  • Strategic Influence: Ability to define security strategy for multiple business units and influence stakeholders from DevOps to the C-Suite.
  • Communication: Skilled at translating "security-speak" into actionable business logic for non-technical partners.
  • Analytical Rigor: A proactive problem-solver who doesn't just find holes but builds the patches and the processes to prevent them. *LI-Y

Benefits & conditions

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $218,400 - $365,200 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $263,200 - $401,400 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable. Applied = 0 MORE JOBS LIKE THIS

About the company

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Apply for this position