
Business Information Security Officer
Salesforce
full-time
Posted on:
Location Type: Office
Location: San Francisco • California • Washington • United States
Visit company websiteExplore more
Salary
💰 $207,800 - $285,800 per year
Tech Stack
About the role
- Partner with AiE leadership to prioritize security risks within the context of mission-critical availability
- Be the "Voice of Security" for operational teams where availability is intrinsically linked to security
- Champion "Security for Operations" mindset, ensuring incident response frameworks, observability pipelines, and change management processes are robust against both adversarial threats and operational errors
- Integrate "Security as Code" within CI/CD and release pipelines
- Govern the use of AI in operations to automate security defenses and support operational resiliency
- Secure the foundation of our business—our "Hyperforce" architecture—operating as the "Voice of Security" embedded with our most critical engineering teams
- Partner with HPS leadership and architects to translate complex risks into engineering reality
- Bring a "platform" mindset, understanding that security controls at the platform and infrastructure layer deliver exponential scale and value to downstream cloud tenants
- Bridge the gap between "architectural risks" (multi-substrate security, cloud dependencies) and "operational risks" (patch management, configuration drift)
- Foster a culture where security is indistinguishable from quality
- Ensure risk decisions are deeply informed by specific technical context, constraints, and capabilities of our systems
- Deliver regular, metric-driven readouts on security risk posture, actively maintain the Security Risk Register, and lead security due diligence for remediation timelines
- Foster a culture of shared security responsibility by integrating security and compliance requirements throughout the infrastructure lifecycle
Requirements
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field (equivalent experience may be considered)
- 10+ years of professional experience in security risk management, with at least 5 years dedicated to security operational roles supporting major cloud platforms (AWS, GCP, or multi-cloud environments)
- Exceptional executive presence, negotiation, and influence skills with ability to partner at VP+ level without direct authority
- High risk acumen and extensive experience managing complex portfolios of security risks
- Strong working knowledge of industry standards and regulations (NIST CSF, ISO 27001, SOC 2, NIST 800-160, ISO 27035, ITIL v4, DORA)
- Proven ability to build strong partnerships across all security functions (CSOC, Product Security, GRC, Enterprise Security)
- Strong understanding of CI/CD security, infrastructure-as-code, and zero-trust architecture principles
- Experience acting as a key stakeholder during major security incidents, managing executive escalations, and driving post-incident remediation
Benefits
- time off programs
- medical
- dental
- vision
- mental health support
- paid parental leave
- life and disability insurance
- 401(k)
- employee stock purchasing program
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security risk managementCI/CD securityinfrastructure-as-codezero-trust architectureincident response frameworksobservability pipelineschange management processescloud platformssecurity controlssecurity due diligence
Soft Skills
executive presencenegotiation skillsinfluence skillsrisk acumenpartnership buildingshared security responsibilitycommunication skillsleadershipcollaborationproblem-solving