Lead Security Consultant - Professional Services Security Assurance (PSSA)

Salesforce.com, Inc.
New York, NY, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$180,200.0 - $247,900.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Software System Penetration Testing C Sharp (Programming Language) Cloud Computing Cloud Computing Security Cyber Security Computer Programming Python (Programming Language) Open Web Application Security
+13 more
PCI Data Security Standards Secure Coding Software Engineering TypeScript Web Applications Scripting Multi-Agent Systems Software Security Mitre Att&ck Information Technology Security Orchestration, Automation & Response Vulnerability Analysis Microservices

Job description

As a hands-on technical expert, you will act as a force multiplier for our PSSA organization. Your primary focus is the delivery of high-impact security engagements directly to our customers, translating complex technical risks into actionable security postures.

What You’ll Do

  • Lead customer engagements by performing in-depth, high-quality security assessments of web, mobile, API, cloud, and AI-enabled applications - including architecture and design reviews, threat modeling, secure code reviews, and penetration testing.
  • Conduct threat modeling exercises to identify potential attack vectors, evaluate business risk, and recommend security controls that effectively balance security, usability, and business objectives.
  • Develop comprehensive security assessment reports that clearly communicate findings, risk ratings, and actionable remediation recommendations to both technical and executive stakeholders.
  • Serve as a trusted security advisor to customers by providing practical remediation guidance, security best practices, and recommendations that improve the overall security posture of their applications and services.
  • Collaborate closely with the professional services org to integrate security throughout the software development lifecycle, from design through deployment.
  • Develop and enhance assessment methodologies, automation, and security tooling to improve assessment quality, consistency, and scalability across customer engagements.
  • Define and contribute to technical security standards, reference architectures, and secure development guidelines in partnership with internal teams and customers.
  • Research emerging technologies, evolving attack techniques, and security vulnerabilities to continuously improve assessment methodologies and provide proactive security recommendations.
  • Build strong customer relationships through effective communication, technical leadership, and consultative engagement throughout the assessment lifecycle.

Requirements

  • Senior: 5+ years of experience in Application Security, Product Security, or Security Consulting
  • Lead: 8+ years of experience in Application Security, Product Security, or Security Consulting
  • Hands-on experience performing application security assessments, including architecture and design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews.
  • Strong understanding of common application security vulnerabilities and secure development practices, including the OWASP Top 10, API Security Top 10, and common attack techniques.
  • Experience assessing modern application architectures, including web applications, APIs, microservices, containers, cloud-native environments, and AI-enabled applications.
  • Experience communicating security findings, risk, and remediation guidance to technical and executive stakeholders.
  • Strong customer-facing consulting skills with the ability to build trusted relationships and influence security outcomes across diverse organizations.
  • Excellent analytical, problem-solving, collaboration, written, and verbal communication skills.
  • Proficiency in one or more programming or scripting languages such as Java, Python, JavaScript/TypeScript, Go, or C#.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related technical field - or equivalent practical experience.

Even Better If You Have…

  • Experience assessing AI applications and agentic systems.
  • Experience developing security automation, reusable assessment frameworks, or security tooling to improve assessment quality and scale.
  • Familiarity with industry security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, and MITRE ATT&CK.
  • Experience defining and communicating prioritized remediation plans and partnering with engineering teams to drive security improvements.
  • Experience mentoring security consultants or leading technical customer engagements.

Benefits & conditions

benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $150,100 - $227,000 annually There is a different range applicable to specific work locations. In California and New York, and select cities in the metropolitan areas of Boston, Chicago, Seattle, and Washington DC, the base pay range for this role in those locations is $180,200 - $247,900 per year. Your recruiter can share more about the specific salary range for the job location during the hiring process. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

About the company

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

About the Team

We are building a brand new Professional Services Security Assurance (PSSA) team - a true 0 to 1 opportunity. This team sits within the Security Practice, part of the broader Professional Services organization. Our mission is to empower the Professional Services organization to deliver secure implementations and protect customer data at scale. We focus on securing the configurations, integrations, and implementations delivered to our customers. As a founding, hands-on technical member of the Security Assurance team within our Security Practice, you will deliver direct security engagements to our customers, ensuring every deployment is secure by design - and shaping the strategic foundation of our practice., Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

1:00 min

Misconceptions about TypeScript safety capabilities

Simone Sanfratello · JS Congress

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

2:55 min

Gaining TypeScript benefits using JSDoc alternatives

Simone Sanfratello · JS Congress

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all