> Markdown version of [/jobs/ext/2626183-security-problem-management-principal](https://www.wearedevelopers.com/jobs/ext/2626183-security-problem-management-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Problem Management Principal - **Company:** Salesforce.com, Inc. - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $197,300.0 - $313,700.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Operational Data Store, Reliability Engineering, Software Vulnerability Management - **Published:** August 22, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18041322?backUrl=%2Fcareer%2F18041322%2FSecurity-Problem-Management-Principal-Virginia-Mclean ## About the Role The Security Problem Management Principle leads the identification, analysis, and resolution of systemic security problems. This role works across Security, Engineering, Infrastructure, Product, and Risk teams to determine root causes, prevent recurrence, and ensure corrective actions are completed. The ideal candidate combines security knowledge, structured problem-solving, program management, and the ability to influence technical and business stakeholders. They promote a blameless learning culture while maintaining clear ownership and accountability for risk reduction., This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role., * 10+ years of experience in cybersecurity, security operations, incident response, problem management, risk management, reliability engineering, or a related discipline. * Strong understanding of security incidents, vulnerabilities, controls, threat scenarios, and technical risk. * Demonstrated experience facilitating root-cause analyses or post-incident reviews. * Ability to translate complex technical findings into clear business risks, decisions, and actions. * Strong program-management skills, including ownership tracking, prioritization, dependency management, and executive communication. * Ability to work effectively across engineering, operations, product, legal, compliance, and leadership teams. * Excellent written and verbal communication skills. * Sound judgment and the ability to challenge incomplete analyses or insufficient remediation constructively. Even Better If You Have: * Experience in a large-scale cloud, SaaS, or enterprise technology environment. * Familiarity with security operations centers, incident-command practices, vulnerability management, and threat intelligence. * Knowledge of frameworks such as NIST CSF, NIST 800-61, ISO 27001, ITIL, or similar standards. * Experience with operational data analysis, dashboards, case-management systems, or work-tracking tools. * Relevant certifications such as CISSP, CISM, CRISC, GIAC, ITIL, or PMP. This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position. ## Description * Own the end-to-end security problem management lifecycle, from problem identification through closure and effectiveness validation. * Identify recurring incidents, control failures, vulnerabilities, and operational trends that require deeper investigation. * Facilitate root-cause analyses and post-incident reviews using structured methods such as five whys, fault-tree analysis, and causal analysis. * Create and maintain high-quality problem records containing impact, contributing factors, root cause, risk, corrective actions, owners, and deadlines. * Distinguish root causes from symptoms and ensure remediation addresses systemic weaknesses. * Partner with incident response teams to transition significant incidents into formal problem investigations. * Track corrective and preventive actions to completion, escalating overdue or blocked work when necessary. * Validate that remediation is effective and has not merely transferred risk to another system or team. * Analyze incident, vulnerability, and control-failure data to identify emerging patterns and systemic risks. * Develop metrics and reporting for senior leadership, including recurrence rates, remediation aging, overdue actions, and risk reduction. * Improve problem-management processes, standards, templates, tooling, and governance. * Promote blameless reviews that encourage transparency, learning, and sustainable engineering improvements. * Maintain alignment with security policies, risk-management requirements, and relevant regulatory obligations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Dos and don'ts with react hooks. An opinionated approach](https://www.wearedevelopers.com/videos/957-dos-and-don-ts-with-react-hooks-an-opinionated-approach) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)