Director, BISO - Enterprise Security
What you'll need to apply
Fields this application requires
Company-specific questions
- Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
- Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
- I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
- Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
Location
NY, SF, Bellevue
The Experience
Salesforce's Enterprise Security organization is looking for a Director, Enterprise Security, Business Information Security Officer (BISO), also known as a Security Partner. In this role, you're accountable for the security posture of major Enterprise Business Units (BUs).
You're the primary point of contact between your BU customers and the broader Security organization, personally accountable for making your customer measurably more secure over time.
This is a senior technical leadership position, not a relationship-management or governance-only seat. You read the designs, understand the systems, and take positions on architecture, controls, and trade-offs, holding well-reasoned technical points of view in rooms full of engineers, architects, product leaders, and executives.
You own the final calls on risk prioritization and remediation sequencing for your portfolio, and you lead a small team of Security Partner professionals.
Success in this role requires deep technical fluency across cloud, identity, application, and artificial intelligence/machine learning (AI/ML) security, sound business judgment when prioritizing risk, and the ability to influence senior stakeholders across engineering, product, legal, privacy, compliance, and finance.
What You'll Actually Be Doing
- Own the end-to-end security relationship for your assigned Business Unit (BU), serving as the primary point of contact and credible voice between BU leadership and Enterprise Security.
- Own the risk register for your portfolio — setting severity, prioritization, and remediation sequencing, and building resourced plans with named owners and dates.
- Lead security engagement on design reviews, threat models, and architecture decisions, shaping secure-by-design patterns early in the development lifecycle.
- Lead the customer's side of active security incidents, coordinating with the Cybersecurity Operations Center (CSOC) and executive stakeholders, while managing and developing a team of Security Partner professionals.
You're Our Person If...
- You have 12+ years of experience in cybersecurity, IT risk, or a related discipline, including significant time in a large, complex enterprise, with prior experience as a BISO, Security Partner, or equivalent senior security leadership role.
- You have deep technical fluency across cloud, identity, application, and AI/ML security, with the ability to hold a substantive technical point of view in design reviews and threat models.
- You have a track record of prioritizing and communicating risk with executive-grade written and verbal communication, including experience representing security to CISO, CIO, GM, and Board-level audiences.
- You have experience managing and developing security professionals, and operating effectively under ambiguity in a fast-moving, cross-functional environment.
Even Better If...
- You hold a CISSP, CISA, CISM, or equivalent certification.
- You have experience in regulated industries or product lines, such as financial services, public sector, or healthcare.
- You have prior experience integrating acquired entities or divestitures into enterprise security programs.
- You have working knowledge of regulatory frameworks such as FedRAMP, SOX, or regional data-protection regimes, and control frameworks such as NIST CSF or NIST SP 800-53.