BISO, Product Security
About the role
Salesforce's Product Security team is seeking a Business Information Security Officer (BISO) to manage stakeholder expectations and business risk for the Business Units and product engineering. This role requires a blend of real-world experience and deep knowledge in software security, including application security, cloud security, secure coding practices, and security architecture.
Responsibilities
- Manage stakeholder expectations and business risk for the Business Units and product engineering
- Drive security initiatives and improve risk posture
- Optimize and track the execution of the security backlog via a single work stream for product engineering
- Work with a broad set of executive stakeholders across business units and security teams
- Take ownership of security initiatives and drive results with minimal supervision
- Translate complex security concepts into business-friendly language
- Cultivate strong working relationships with customer teams and internal security teams, including those in international locations
- Thrive in a dynamic, fast-paced environment, staying ahead of emerging threats and adapting strategies to evolving business needs
Requirements
- 10-15 years of experience in information security, with at least 5-10 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third-party integrations
- Deep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third-party risk management frameworks
- Familiarity with security tools such as SIEM: Splunk specifically, vulnerability scanners (e.g., Qualys, Nessus), or IAM solutions (e.g., Okta, SailPoint)
- Strong executive presence and ability to articulate technical security concepts in a business/risk context
- Customer-focused: Ability to balance "get it done" attitude with diplomacy to work effectively across different teams and at all levels
- Proven ability to prioritize initiatives utilizing risk data from multiple input sources, while staying aligned with the bigger picture
- Strong understanding of security and compliance frameworks (e.g., SOX, NIST CSF, ISO 27001/2, CIS Controls)
- Excellent communication skills to translate complex security concepts into business-friendly language
- Strong stakeholder management and collaboration skills to work with cross-functional teams and ability to influence decision-making without direct authority
Qualifications
- Related technical degree required
- Deep understanding of securing AI solutions
- Prior experience as BISO or equivalent is desirable
- Strong willingness to challenge status quo and drive continuous improvement through change and new ideas
- Track record of auditing related or consulting experience, high tech industry a plus
- Certifications like CISM or CISSP highly desired
Skills
- Experience in software security, application security, cloud security, secure coding practices, and security architecture
- Knowledge of security principles across all tech layers, including cloud platforms, infrastructure security, application security, and third-party risk management frameworks
- Experience with security tools such as SIEM, vulnerability scanners, and IAM solutions
- Strong executive presence and ability to articulate technical security concepts in a business/risk context
- Customer-focused communication skills
- Stakeholder management and collaboration skills
- Understanding of security and compliance frameworks
- Ability to thrive in a dynamic, fast-paced environment
Benefits
At Salesforce, we offer a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. For more details, visit here.
Pay
The typical base salary range for this position is $197,300 - $313,700 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.
Schedule
Not specified.