Salesforce
Business Information Security Officer (BISO), Product Security
Role Type: Individual Contributor (IC)
About Our Team Salesforce's Product Security team within the broader Security organization is at the forefront of securing our customer data and assets while balancing risk and security posture. We thrive on collaboration with product and engineering teams to drive risk outcomes and help maintain trust for our customers.
Your Impact – Responsibilities This pivotal BISO role requires a blend of real‑world experience and deep knowledge in software security, including application security, cloud security, secure coding practices, and security architecture, with a specific focus on AI security across SaaS and on‑premise services.
The ideal candidate will have a proven track record of excellence in security delivery and the ability to work with a broad set of executive stakeholders across Business Units and Security teams to drive security initiatives and improve risk posture. This role is responsible for managing stakeholder expectations and business risk for the Business Units and can prioritize, optimize, and track the execution of the security backlog via a single work stream for product and engineering, using deep technical understanding and business risk impact.
Minimum Qualifications
Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field. Equivalent experience may be considered.
10‑15 years of experience in information security, with at least 5‑10 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third‑party integrations.
Deep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third‑party risk management frameworks.
Familiarity with security tools such as SIEM (e.g., Splunk, QRadar), vulnerability scanners (e.g., Qualys, Nessus), or IAM solutions (e.g., Okta, SailPoint).
Demonstrated ability to work independently, take ownership of security initiatives, and drive results with minimal supervision.
Strong executive presence and immaculate ability to articulate technical security concepts in a business/risk context.
Customer‑focused: balance a “get it done” attitude with diplomacy to work effectively across different teams and at all levels.
Proven ability to prioritize initiatives utilizing risk data from multiple input sources, while staying aligned with the bigger picture.
Strong understanding of security and compliance frameworks (e.g., SOX, NIST CSF, ISO 27001/2, CIS Controls).
Ability to thrive in a dynamic, fast‑paced environment, staying ahead of emerging threats and adapting strategies to evolving business needs.
Excellent communication skills to translate complex security concepts into business‑friendly language.
Strong stakeholder management and collaboration skills to work with cross‑functional teams and influence decision‑making without direct authority.
Preferred Qualifications
Deep understanding of securing AI solutions.
Prior experience as BISO or equivalent is desirable.
Ability to cultivate strong working relationships with customer teams and internal security teams, including those in international locations.
Strong willingness to challenge status quo and drive continuous improvement through change and new ideas.
Track record of auditing, consulting experience; high‑tech industry a plus.
Certifications like CISM or CISSP highly desired.
Accommodations Applicants with disabilities may request accommodations via the Accommodations Request Form.
Equal Opportunity Statement Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants.
Salary For Washington‑based roles, base salary range: $211,500 to $306,600.
For California‑based roles, base salary range: $230,800 to $334,600.
#J-18808-Ljbffr
About Our Team Salesforce's Product Security team within the broader Security organization is at the forefront of securing our customer data and assets while balancing risk and security posture. We thrive on collaboration with product and engineering teams to drive risk outcomes and help maintain trust for our customers.
Your Impact – Responsibilities This pivotal BISO role requires a blend of real‑world experience and deep knowledge in software security, including application security, cloud security, secure coding practices, and security architecture, with a specific focus on AI security across SaaS and on‑premise services.
The ideal candidate will have a proven track record of excellence in security delivery and the ability to work with a broad set of executive stakeholders across Business Units and Security teams to drive security initiatives and improve risk posture. This role is responsible for managing stakeholder expectations and business risk for the Business Units and can prioritize, optimize, and track the execution of the security backlog via a single work stream for product and engineering, using deep technical understanding and business risk impact.
Minimum Qualifications
Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field. Equivalent experience may be considered.
10‑15 years of experience in information security, with at least 5‑10 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third‑party integrations.
Deep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third‑party risk management frameworks.
Familiarity with security tools such as SIEM (e.g., Splunk, QRadar), vulnerability scanners (e.g., Qualys, Nessus), or IAM solutions (e.g., Okta, SailPoint).
Demonstrated ability to work independently, take ownership of security initiatives, and drive results with minimal supervision.
Strong executive presence and immaculate ability to articulate technical security concepts in a business/risk context.
Customer‑focused: balance a “get it done” attitude with diplomacy to work effectively across different teams and at all levels.
Proven ability to prioritize initiatives utilizing risk data from multiple input sources, while staying aligned with the bigger picture.
Strong understanding of security and compliance frameworks (e.g., SOX, NIST CSF, ISO 27001/2, CIS Controls).
Ability to thrive in a dynamic, fast‑paced environment, staying ahead of emerging threats and adapting strategies to evolving business needs.
Excellent communication skills to translate complex security concepts into business‑friendly language.
Strong stakeholder management and collaboration skills to work with cross‑functional teams and influence decision‑making without direct authority.
Preferred Qualifications
Deep understanding of securing AI solutions.
Prior experience as BISO or equivalent is desirable.
Ability to cultivate strong working relationships with customer teams and internal security teams, including those in international locations.
Strong willingness to challenge status quo and drive continuous improvement through change and new ideas.
Track record of auditing, consulting experience; high‑tech industry a plus.
Certifications like CISM or CISSP highly desired.
Accommodations Applicants with disabilities may request accommodations via the Accommodations Request Form.
Equal Opportunity Statement Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants.
Salary For Washington‑based roles, base salary range: $211,500 to $306,600.
For California‑based roles, base salary range: $230,800 to $334,600.
#J-18808-Ljbffr