Salesforce

Business Information Security Officer

Salesforce

full-time

Posted on:

Location Type: Office

Location: San FranciscoCaliforniaWashingtonUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $207,800 - $285,800 per year

Job Level

About the role

  • Partner with AiE leadership to prioritize security risks within the context of mission-critical availability
  • Be the "Voice of Security" for operational teams where availability is intrinsically linked to security
  • Champion "Security for Operations" mindset, ensuring incident response frameworks, observability pipelines, and change management processes are robust against both adversarial threats and operational errors
  • Integrate "Security as Code" within CI/CD and release pipelines
  • Govern the use of AI in operations to automate security defenses and support operational resiliency
  • Secure the foundation of our business—our "Hyperforce" architecture—operating as the "Voice of Security" embedded with our most critical engineering teams
  • Partner with HPS leadership and architects to translate complex risks into engineering reality
  • Bring a "platform" mindset, understanding that security controls at the platform and infrastructure layer deliver exponential scale and value to downstream cloud tenants
  • Bridge the gap between "architectural risks" (multi-substrate security, cloud dependencies) and "operational risks" (patch management, configuration drift)
  • Foster a culture where security is indistinguishable from quality
  • Ensure risk decisions are deeply informed by specific technical context, constraints, and capabilities of our systems
  • Deliver regular, metric-driven readouts on security risk posture, actively maintain the Security Risk Register, and lead security due diligence for remediation timelines
  • Foster a culture of shared security responsibility by integrating security and compliance requirements throughout the infrastructure lifecycle

Requirements

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field (equivalent experience may be considered)
  • 10+ years of professional experience in security risk management, with at least 5 years dedicated to security operational roles supporting major cloud platforms (AWS, GCP, or multi-cloud environments)
  • Exceptional executive presence, negotiation, and influence skills with ability to partner at VP+ level without direct authority
  • High risk acumen and extensive experience managing complex portfolios of security risks
  • Strong working knowledge of industry standards and regulations (NIST CSF, ISO 27001, SOC 2, NIST 800-160, ISO 27035, ITIL v4, DORA)
  • Proven ability to build strong partnerships across all security functions (CSOC, Product Security, GRC, Enterprise Security)
  • Strong understanding of CI/CD security, infrastructure-as-code, and zero-trust architecture principles
  • Experience acting as a key stakeholder during major security incidents, managing executive escalations, and driving post-incident remediation
Benefits
  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
security risk managementCI/CD securityinfrastructure-as-codezero-trust architectureincident response frameworksobservability pipelineschange management processescloud platformssecurity controlssecurity due diligence
Soft Skills
executive presencenegotiation skillsinfluence skillsrisk acumenpartnership buildingshared security responsibilitycommunication skillsleadershipcollaborationproblem-solving