Job Closed
This listing is no longer active.
👋 We're Salesforce, the customer company. CRM + Data + AI + Trust.
Senior Practices Director – Technical Security Assessment
Location
California + 3 moreAll locations: California | Illinois | New Jersey | Washington
Posted
138 days ago
Salary
$191.1K - $320.6K / year
Seniority
Senior
Job Description
Senior Practices Director – Technical Security Assessment
Salesforce
• Synthesize information from the industry regarding potential attack vectors and proactively advise on related security controls impacting SAAS apps. • Advise customers on securing their Salesforce environment across the digital supply chain, identifying risks in third-party integrations, AppExchange packages, and connected middleware. • Define technical security standards and "Gold Standard" implementation guides to ensure consistent quality across the practice. • Lead architecture reviews, code reviews, and penetration tests across diverse environments (Web Apps, SaaS, and Mobile). • Conduct workshops to identify design flaws and develop mitigation techniques that balance strict security requirements with business agility. • Collaborate with engineering teams to "shift security left," integrating automated security scanning (SAST/DAST) into CI/CD pipelines. • Develop automated tooling (scripts, scanners) to identify vulnerabilities and solve security problems at scale. • Design robust authentication and authorization flows using modern protocols (SAML, OAuth, OIDC) to secure access to the platform.
Job Requirements
- 10+ Years of experience in a dedicated security role (Security Engineering, AppSec, Incident Response, or Red/Blue Teaming).
- Proficiency with standard security assessment tools such as BurpSuite, Nexpose, Nessus, Metasploit, or Nmap.
- Experience performing manual and tool-assisted code reviews in Java, JavaScript, Python, or similar languages.
- Hands-on experience securing and testing public cloud environments (AWS, Azure, GCP) and understanding the Shared Responsibility Model.
- Deep knowledge of network security models, encryption standards (PKI, TLS), and identity protocols (SAML, OAuth, Kerberos).
- Familiarity with OWASP Top 10 vulnerabilities and modern defense techniques.
- Certifications (Candidates should possess one or more of the following): CISSP (Certified Information Systems Security Professional) – Demonstrates senior-level architectural breadth. CCSP (Certified Cloud Security Professional) – Critical for understanding SaaS/PaaS security models. OSCP (Offensive Security Certified Professional) or GPEN – Demonstrates hands-on "hacker mindset" and technical capability. GWAPT (GIAC Web Application Penetration Tester) CISM (Certified Information Security Manager).
Benefits
- time off programs
- medical
- dental
- vision
- mental health support
- paid parental leave
- life and disability insurance
- 401(k)
- employee stock purchasing program
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer
AutomoxAll your endpoints. Always configured. Always secured. Cloud-native IT operations for modern organizations.
• Build proactive security automation aimed at decreasing manual remediation work. • Research new and novel ways to accomplish security work and publish your findings on our blog. • Participate in a monthly security on-call rotation for critical escalations. • Build security capabilities utilizing the attacker mindset and other adversary research.
Cybersecurity Specialist – Corporate Security
Grupo OLXBuscamos o novo para ir além! Vem reinventar a sua carreira com a gente!
• We are seeking a Cyber Security Specialist focused on corporate security to help protect the company’s assets, users and infrastructure, with a strong emphasis on preventive controls, detection and incident response. • This professional will play a key role in operating and evolving security controls for the corporate environment, working in partnership with IT, infrastructure and security teams. • Creation, review and maintenance of firewall rules and policies; • Definition, implementation and management of DLP policies and rules, with a focus on Netskope; • Support, installation, configuration, monitoring and analysis of EDR solutions, especially CrowdStrike; • Management of the corporate office network, including troubleshooting and continuous improvement; • Administration and support of the corporate VPN; • Experience with Patch Management tools, including vulnerability tracking and applying remediations; • Support and administration of Active Directory (users, groups, permissions and policies); • Configuration, support and evolution of ZTNA (Zero Trust Network Access) solutions; • Assistance in investigating and responding to security incidents related to the corporate environment; • Documentation of security processes, policies and procedures.
Enterprise Security Architect
Navitus Health SolutionsWe are committed to helping humans by making medications more affordable for the people who need them.
• Act as subject matter expert on infrastructure, security and network architecture. • Serve as a security team advisor on corporate projects, providing technical security consultations on highly complex business projects. • Research utilization and capacity planning of existing technologies to plan for future growth. • Analyze and design effective and clear technical solutions for infrastructure and enterprise security related projects. • Collaborate with other IT teams to perform a Proof of Concept for solutions that show promise. • Assist in the development and implementation of corporate information security policies and procedures, strategies, including deployment, administration, configuration and support of security related systems. • Maintain knowledge in Infrastructure Operations, Data Center Operations, Virtualization (Server, Network, Storage, Desktop, and Application); attend conferences, meet with vendors, and keep current on technology trends. • Analyze, provide guidance and diagnose security incidents and may cause a threat to Navitus’s security and safety. • Recognized as a system expert in multiple core enterprise systems and be able to effectively provide knowledge training to peers. • On-call availability. Some travel may be required. Provide after-hours support. Other duties as assigned.
Security Engineer
ExodusControl Your Wealth: Secure, Manage, and Swap your blockchain assets in one wallet.
• Build smart, AI-assisted automation that reduces manual security work • Connect and enrich security data across enterprise and security tools • Help improve how quickly and confidently alerts are understood and prioritized • Play an active role in security hardening, investigations and incident response • Create scalable automation that makes the Cyber Defense team more effective • Continuously reduce attack surface across enterprise and production environments




