Skip to content
← Back to job listings

Product Security Lead

Salesforce · Bellevue, United States

Imported listingfull-time16 days ago

About The Role

Join Salesforce's Platform Security team as a Product Security Lead. In this hands-on role, you will be the technical security lead for the user-facing application and experience layers of the platform. You will drive security assurance, shape security controls, and serve as a trusted security voice to a top-tier Engineering organization. You will also own AI and agentic risk, mitigating threats and defining security standards.

  • Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review across web and UI frameworks.
  • Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security.
  • Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions.
  • You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go)
  • You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolution
  • You can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product work
  • You have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfaces
  • You've secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaS
  • You've done hands-on work with LLM application security, agent frameworks, or MCP
  • You've owned a security program or served as the standing security lead for a product area
  • You have bug bounty or red-team experience

This is an external listing. JobSpring does not represent or verify the employer. Report this listing