Lead Security Consultant - Professional Services Security Assurance (PSSA)

Salesforce Inc.
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Tech stack

Java
JavaScript
API
Artificial Intelligence
Software System Penetration Testing
C Sharp (Programming Language)
Cloud Computing
Cloud Computing Security
Cloud Engineering
Computer Security
Python
Open Web Application Security
Salesforce
Secure Coding
Software Engineering
TypeScript
Web Applications
Software Security
Information Technology
Vulnerability Analysis
Microservices

Job description

Experteer Overview As a hands-on technical expert in the PSSA team, you will deliver secure engagements for Salesforce customers, translating complex risks into actionable security postures. You'll lead security assessments across web, mobile, API, cloud, and AI-enabled apps, shaping secure deployment practices. You'll act as a trusted advisor, guiding remediation and best practices while collaborating with the broader services organization. This is a founding, high-impact role with opportunities to influence security standards and tooling. Compensation / Benefits * Lead security assessments (architecture/design reviews, threat modeling, secure code reviews, pentesting) for web, mobile, API, cloud, and AI-enabled apps * Conduct threat modeling to identify attack vectors and balance security with usability and business goals * Produce comprehensive reports with findings, risk ratings, and remediation guidance for technical and executive stakeholders * Act as a trusted security advisor, providing practical remediation guidance and security best practices * Integrate security across the software development lifecycle with the professional services organization * Develop and enhance assessment methodologies, automation, and tooling for quality and scalability * Define and contribute to technical security standards, reference architectures, and secure development guidelines * Research emerging security threats and technologies to improve methodologies and recommendations * Build strong customer relationships through effective communication, leadership, and consultative engagement Tasks * Senior: 5+ years in Application Security, Product Security, or Security Consulting; Lead: 8+ years * Hands-on experience with app security assessments including architecture/design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews * Strong knowledge of OWASP Top 10, API Security Top 10, and common attack techniques * Experience with modern architectures: web apps, APIs, microservices, containers, cloud-native, and AI apps * Experience communicating findings and remediation to technical and executive stakeholders * Strong customer-facing consulting skills to influence security outcomes * Excellent analytical, problem-solving, collaboration, written and verbal communication * Proficiency in Java, Python, JavaScript/TypeScript, Go, or C# * Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent practical experience Key requirements * medical, dental, vision * mental health support * paid parental leave * life and disability insurance * 401(k) * employee stock purchasing program

Requirements

  • providing practical remediation guidance and security best practices * Integrate security across the software development lifecycle with the professional services organization * Develop and enhance assessment methodologies, automation, and tooling for quality and scalability * Define and contribute to technical security standards, reference architectures, and secure development guidelines * Research emerging security threats and technologies to improve methodologies and recommendations * Build strong customer relationships through effective communication, leadership, and consultative engagement Tasks * Senior: 5+ years in Application Security, Product Security, or Security Consulting; Lead: 8+ years * Hands-on experience with app security assessments including architecture/design reviews, threat modeling, secure code reviews, penetration testing, and cloud security reviews * Strong knowledge of OWASP Top 10, API Security Top 10, and common attack techniques * Experience with modern aaaaa FULL_TIME web apps, APIs, microservices, containers, cloud-native, and AI apps * Experience communicating findings and remediation to technical and executive stakeholders * Strong customer-facing consulting skills to influence security outcomes * Excellent analytical, problem-solving, collaboration, written and verbal communication * Proficiency in Java, Python, JavaScript/TypeScript, Go, or C# * Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent practical experience Key requirements * medical, dental, vision * mental health support * paid parental leave * life and disability insurance * 401(k) * employee stock purchasing program

Apply for this position