BISO, Product Security
$197,300–$313,700 year
On-siteSeattle, Washington, United States or Bellevue, Washington, United States
Job Summary
Manage business unit risk and prioritize the security backlog via a single work stream for product engineering, balancing stakeholder expectations while optimizing security delivery. Lead technical security initiatives across cloud, infrastructure, applications, and third-party integrations, translating complex concepts into business risk for executive stakeholders. Drive continuous improvement in application security, secure coding, and compliance frameworks like NIST CSF and ISO 27001/2. This pivotal role within Salesforce's Product Security team requires a BISO to maintain trust for customers while navigating the agentic era of AI. You will collaborate with cross-functional teams to influence decision-making and ensure robust risk outcomes across Software as a Service and On-premise services.
Required Qualifications
- 10-15 years of experience in information security
- at least 5-10 years in a leadership role focused on technical security across cloud, infrastructure, applications, and third-party integrations
- Deep understanding of security principles across all tech layers, including cloud platforms (AWS, Azure, GCP), infrastructure security (network, endpoint, IAM), application security (SAST, DAST, secure coding), and third-party risk management frameworks
- Familiarity with security tools such as SIEM: Splunk specifically, vulnerability scanners (e.g., Qualys, Nessus), or IAM solutions (e.g., Okta, SailPoint)
- Demonstrated ability to work independently, take ownership of security initiatives, and drive results with minimal supervision
- Strong executive presence and immaculate ability to articulate technical security concepts in a business/risk context
- Proven ability to prioritize initiatives utilizing risk data from multiple input sources, while staying aligned with the bigger picture
- Strong understanding of security and compliance frameworks (e.g., SOX, NIST CSF, ISO 27001/2, CIS Controls)
- Ability to thrive in a dynamic, fast-paced environment, staying ahead of emerging threats and adapting strategies to evolving business needs
- Excellent communication skills to translate complex security concepts into business-friendly language
- Strong stakeholder management and collaboration skills to work with cross-functional teams and ability to influence decision-making without direct authority
- A related technical degree
Desired Qualifications
- Deep understanding of securing AI solutions
- Prior experience as BISO or equivalent
- Ability to cultivate strong working relationships with customer teams and internal security teams, including those in international locations
- Strong willingness to challenge status quo and drive continuous improvement through change and new ideas
- Track record of auditing related or consulting experience
- high tech industry
- Certifications like CISM or CISSP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.