Senior Level Product Security Engineer Jobs
Senior level product security engineer jobs place experienced engineers in charge of security architecture decisions, threat modeling at scale, and the cross-functional initiatives that protect products from design through deployment. Openings cover 57% remote and hybrid arrangements across Technology & Software, Electronics & Hardware, and Retail, with employers like SanDisk, DigitalOcean, and Microchip Technology hiring at this level now.
Find JobsOverview
Showing 5 of 27+ Senior Level Product Security Engineer jobs











To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
ProductJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Salesforce's Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on. We are hands-on security engineers who collaborate closely with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world's #1 CRM platform secure. This role serves as the technical security lead for the user-facing application and experience layers of the platform, including front-end frameworks, runtimes, and rendering surfaces that developers use to author and run experiences. It also covers fast-growing AI agent-driven experiences and web data-access surfaces that render across our own surfaces, third-party channels, and external agentic clients. You'll set the security assurance bar across these areas. You'll shape how controls are designed and drive secure-by-default patterns upstream. You'll serve as a trusted security voice to a top-tier Engineering organization delivering multi-release, cross-team programs, at a time when this layer's trust model is being redefined.
What You'll Actually Be Doing
- Lead security assurance for the experience and UI layer, driving threat modeling, security design reviews, and targeted code review (JavaScript/TypeScript, Java) across web and UI frameworks, runtimes, rendering pipelines, and the guest-user-exposed data-access APIs beneath them.
- Serve as the standing security lead for multi-quarter, multi-team programs such as the expansion of guest-user data access, first-party experiences rendering into surfaces we don't control, and the trust model for agent-facing products.
- Push secure patterns into frameworks, SDKs, and rendering pipelines so unsafe patterns are hard to introduce, and author security standards other teams adopt for web/UI security, guest-user data access, and rendering trust boundaries. Own AI and agentic risk, mitigating threats like prompt injection, excessive agency, and context/memory poisoning; design human-in-the-loop gates for high-risk actions; and define least-privilege scoping, audit logging, and short-lived credentials for agent and connector integrations, including for the Model Context Protocol (MCP).
You're Our Person If...
- You have deep expertise in web/application security and the security of modern UI frameworks, web runtimes, or data-access APIs, with hands-on experience finding and eliminating web weakness classes and securing guest-user or unauthenticated surfaces.
- You have threat-modeling experience across complex web, UI, or data-access environments, driven to resolution.
- You can reason about AI/large language model (LLM) or agentic risk — prompt injection, tool/agent abuse, or MCP/connector security — applied to real product work. You have a track record of authoring security standards and leading cross-team, multi-release security programs, with the ability to influence experienced developers, and can fluently review JavaScript/TypeScript plus at least one other modern language (Java, Python, or Go).
Even Better If...
- You've secured UI frameworks, web runtimes, GraphQL/data-access APIs, or rendering frameworks at scale, ideally for a large-scale multi-tenant SaaS.
- You've done hands-on work with LLM application security, agent frameworks, or MCP.
- You've owned a security program or served as the standing security lead for a product area.
- You have bug bounty or red-team experience.
Unleash Your Potential
When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best , and our AI agents accelerate your impact so you can do your best . Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.
Accommodations
If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form .
Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.
Posting Statement
Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.
In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.

The typical base salary range for this position is $172,500 - $260,100 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $207,800 - $285,800 annually.

The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.See All 27 Senior Level Product Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsSenior Level Product Security Engineer Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software13
- Electronics & Hardware5
- Retail1
- Manufacturing1
- Medical Devices1
Senior Level Product Security Engineer Jobs: Frequently Asked Questions
How do I get a senior level product security engineer job?
Employers at this level look for engineers who can own a security domain end to end, not just execute assigned tasks. Demonstrating that you have driven threat modeling programs, influenced product roadmaps, and mentored other engineers will set you apart. Publishing research, contributing to security standards, or holding certifications like CISSP or OSCP strengthens a senior-level candidacy considerably.
Which companies hire senior level product security engineers?
Companies hiring senior level product security engineers right now include SanDisk, DigitalOcean, and Microchip Technology, based on current listings on Migrate Mate as of September 2026. Hiring at this level tends to come from technology companies, financial institutions, and defense contractors that maintain large product portfolios and need engineers who can lead security strategy rather than follow it.
Are there remote senior level product security engineer jobs?
Yes, remote and hybrid arrangements are common at this experience level. About 57% of senior level product security engineer openings are remote or hybrid as of September 2026, reflecting how many organizations treat senior security talent as distributed by default. On-site roles do exist, particularly in regulated industries where security work touches classified or sensitive infrastructure.
What makes a product security engineer role senior level?
Senior level product security engineer roles are defined by scope and ownership. Where mid-level engineers execute security reviews and respond to findings, senior engineers set the security strategy for a product area, define processes that others follow, and lead threat modeling across entire systems. They also mentor junior and mid-level engineers and serve as the primary point of contact between security and product or engineering leadership.
Which industries hire the most senior level product security engineers?
Senior Level product security engineer roles concentrate in Technology & Software, Electronics & Hardware, and Retail, based on current listings on Migrate Mate as of September 2026. These sectors drive hiring at this level because they develop complex, widely deployed products where a security compromise carries significant regulatory, financial, or reputational consequences, creating demand for engineers who can lead rather than just contribute.