> Markdown version of [/jobs/ext/1978062-lead-security-consultant-professional-services-security-assurance-pssa](https://www.wearedevelopers.com/jobs/ext/1978062-lead-security-consultant-professional-services-security-assurance-pssa). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Consultant - Professional Services Security Assurance (PSSA) - **Company:** Salesforce.com, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $180,200.0 - $247,900.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Secure Coding, Software Engineering, TypeScript, Web Applications, Scripting, Multi-Agent Systems, Software Security, Mitre Att&ck, Information Technology, Security Orchestration, Automation & Response, Vulnerability Analysis, Microservices - **Published:** August 7, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87951289/1 ## About the Role * Senior: 5+ years of experience in Application Security, Product Security, or Security Consulting * Lead: 8+ years of experience in Application Security, Product Security, or Security Consulting * Hands-on experience performing application security assessments, including architecture and design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews. * Strong understanding of common application security vulnerabilities and secure development practices, including the OWASP Top 10, API Security Top 10, and common attack techniques. * Experience assessing modern application architectures, including web applications, APIs, microservices, containers, cloud-native environments, and AI-enabled applications. * Experience communicating security findings, risk, and remediation guidance to technical and executive stakeholders. * Strong customer-facing consulting skills with the ability to build trusted relationships and influence security outcomes across diverse organizations. * Excellent analytical, problem-solving, collaboration, written, and verbal communication skills. * Proficiency in one or more programming or scripting languages such as Java, Python, JavaScript/TypeScript, Go, or C#. * Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related technical field - or equivalent practical experience. Even Better If You Have... * Experience assessing AI applications and agentic systems. * Experience developing security automation, reusable assessment frameworks, or security tooling to improve assessment quality and scale. * Familiarity with industry security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, and MITRE ATT&CK. * Experience defining and communicating prioritized remediation plans and partnering with engineering teams to drive security improvements. * Experience mentoring security consultants or leading technical customer engagements. ## Description As a hands-on technical expert, you will act as a force multiplier for our PSSA organization. Your primary focus is the delivery of high-impact security engagements directly to our customers, translating complex technical risks into actionable security postures. What You'll Do * Lead customer engagements by performing in-depth, high-quality security assessments of web, mobile, API, cloud, and AI-enabled applications - including architecture and design reviews, threat modeling, secure code reviews, and penetration testing. * Conduct threat modeling exercises to identify potential attack vectors, evaluate business risk, and recommend security controls that effectively balance security, usability, and business objectives. * Develop comprehensive security assessment reports that clearly communicate findings, risk ratings, and actionable remediation recommendations to both technical and executive stakeholders. * Serve as a trusted security advisor to customers by providing practical remediation guidance, security best practices, and recommendations that improve the overall security posture of their applications and services. * Collaborate closely with the professional services org to integrate security throughout the software development lifecycle, from design through deployment. * Develop and enhance assessment methodologies, automation, and security tooling to improve assessment quality, consistency, and scalability across customer engagements. * Define and contribute to technical security standards, reference architectures, and secure development guidelines in partnership with internal teams and customers. * Research emerging technologies, evolving attack techniques, and security vulnerabilities to continuously improve assessment methodologies and provide proactive security recommendations. * Build strong customer relationships through effective communication, technical leadership, and consultative engagement throughout the assessment lifecycle. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)