Security Problem Management Principal

Salesforce.com, Inc.
McLean, VA, United States
15 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$197,300.0 - $313,700.0
Working hours
Regular working hours

Tech stack

Software as a Service Cyber Security Operational Data Store Reliability Engineering Software Vulnerability Management

Job description

  • Own the end-to-end security problem management lifecycle, from problem identification through closure and effectiveness validation.
  • Identify recurring incidents, control failures, vulnerabilities, and operational trends that require deeper investigation.
  • Facilitate root-cause analyses and post-incident reviews using structured methods such as five whys, fault-tree analysis, and causal analysis.
  • Create and maintain high-quality problem records containing impact, contributing factors, root cause, risk, corrective actions, owners, and deadlines.
  • Distinguish root causes from symptoms and ensure remediation addresses systemic weaknesses.
  • Partner with incident response teams to transition significant incidents into formal problem investigations.
  • Track corrective and preventive actions to completion, escalating overdue or blocked work when necessary.
  • Validate that remediation is effective and has not merely transferred risk to another system or team.
  • Analyze incident, vulnerability, and control-failure data to identify emerging patterns and systemic risks.
  • Develop metrics and reporting for senior leadership, including recurrence rates, remediation aging, overdue actions, and risk reduction.
  • Improve problem-management processes, standards, templates, tooling, and governance.
  • Promote blameless reviews that encourage transparency, learning, and sustainable engineering improvements.
  • Maintain alignment with security policies, risk-management requirements, and relevant regulatory obligations.

Requirements

The Security Problem Management Principle leads the identification, analysis, and resolution of systemic security problems. This role works across Security, Engineering, Infrastructure, Product, and Risk teams to determine root causes, prevent recurrence, and ensure corrective actions are completed.

The ideal candidate combines security knowledge, structured problem-solving, program management, and the ability to influence technical and business stakeholders. They promote a blameless learning culture while maintaining clear ownership and accountability for risk reduction., This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role., * 10+ years of experience in cybersecurity, security operations, incident response, problem management, risk management, reliability engineering, or a related discipline.

  • Strong understanding of security incidents, vulnerabilities, controls, threat scenarios, and technical risk.
  • Demonstrated experience facilitating root-cause analyses or post-incident reviews.
  • Ability to translate complex technical findings into clear business risks, decisions, and actions.
  • Strong program-management skills, including ownership tracking, prioritization, dependency management, and executive communication.
  • Ability to work effectively across engineering, operations, product, legal, compliance, and leadership teams.
  • Excellent written and verbal communication skills.
  • Sound judgment and the ability to challenge incomplete analyses or insufficient remediation constructively.

Even Better If You Have:

  • Experience in a large-scale cloud, SaaS, or enterprise technology environment.
  • Familiarity with security operations centers, incident-command practices, vulnerability management, and threat intelligence.
  • Knowledge of frameworks such as NIST CSF, NIST 800-61, ISO 27001, ITIL, or similar standards.
  • Experience with operational data analysis, dashboards, case-management systems, or work-tracking tools.
  • Relevant certifications such as CISSP, CISM, CRISC, GIAC, ITIL, or PMP.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Benefits & conditions

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $197,300 - $313,700 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

About the company

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:24 min

Managing environmental components via Terraform core architecture

Talia Nassi · LIVE

1:25 min

Computer memory architecture and hardware hierarchy

Alex Gorbunov Alex Gorbunov · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all