Principal Product Security Engineer

Salesforce · California - San Francisco · San Francisco

Spotted 1h agoFull time
Job description

About this role

Employer-provided description, formatted for easier reading.

Job Title: Principal Engineer, Product Security

The Experience

The Product Security team sits within Trust & Security, partnering closely with engineering across Salesforce's fastest-growing cloud products — spanning AI-driven automation, data platforms, and core enterprise services. We act as the last line of defense before features reach customers, embedding security into design rather than patching after the fact.

We are looking for a Principal Engineer, Product Security to serve as the dedicated security authority for several high-growth business units. You will navigate deployment models ranging from multi-tenant SaaS (Software as a Service) to restricted public-sector and private-cloud architectures, build security programs where none exist today, and secure next-generation AI and large language model (LLM) features.

This is a hands-on technical role: you'll review architecture, model threats, read code, and advise engineering leadership directly on risk.

What You'll Be Doing

  • Define and execute the end-to-end product security strategy for assigned business units, building scalable, repeatable review processes where none currently exist.
  • Conduct architecture reviews and threat models for complex cloud environments, data platforms, and regulated public-sector deployments.
  • Review code, system integrations, and AI/LLM gateways directly to identify vulnerabilities and design flaws.
  • Advise engineering leadership on security risk, including recommending a delay to General Availability (GA) when critical requirements are unmet.

Required Qualifications

  • 7-10+ years of hands-on experience in a Product Security, Application Security, or Security Architecture role.
  • Demonstrated experience across Application Security, Cloud Security, and Data Security, including how these domains interact in practice.
  • A track record of building and scaling a security program from the ground up, documented through specific projects you led.
  • Experience reviewing source code and complex data architectures as part of a security assessment.

Preferred Qualifications

  • Experience securing AI/LLM infrastructure, including prompt processing, data boundaries, and AI-specific threat mitigation.
  • Experience securing large-scale data platforms or system integration pipelines.
  • Experience building software for regulated environments such as private-cloud, GovCloud (Government Cloud), or FedRAMP (Federal Risk and Authorization Management Program) deployments.
  • Familiarity with security frameworks such as FedRAMP, SOC 2 (Service Organization Control 2), or NIST CSF (National Institute of Standards and Technology Cybersecurity Framework).
Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce