14 days ago

Cloud Security Architect

Salesforce

On Site
Full Time
$218,400
New York, NY
Apply

Job Overview

Job TitleCloud Security Architect
Job TypeFull Time
Offered Salary$218,400
LocationNew York, NY
Map of New York, NY

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

Job Summary

A key leader, the Cloud Security Architect will drive the security related efforts related to design, implementation, and maintenance of secure cloud environments leveraging cloud-native services and security tooling for proactive risk reduction on GCP and other environments. This role requires deep expertise in public cloud security principles, best practices, and cutting-edge technologies to define security baselines, enforce policies, and embed security into public cloud architectures. You aren't just auditing checklists; you are building the blueprints. This role bridges the gap between Product Security (the "what" we build) and Cloud Infrastructure (the "how" we run it). You will drive the adoption of "Security by Design," ensuring that our GCP-heavy environment is automated, resilient, and proactive against modern threats.

Cloud Security Responsibilities

  • Security Baselines: Define and enforce comprehensive security policies and standards across multi-cloud environments, with a primary focus on GCP.
  • Native Tooling: Architect and implement Google Cloud Native Security Services (Chronicle, Cloud Armor, Cloud IDS, KMS, and Secret Manager).
  • Identity & Governance: Design sophisticated IAM structures and organizational hierarchies to ensure least-privileged access at scale.
  • Detection & Response: Partner with the CSOC to integrate logging and monitoring telemetry into actionable security posture management.

Product Security Responsibilities

  • Threat Modeling: Lead deep-dive threat modeling sessions for new products and features, identifying architectural flaws before a single line of code is deployed.
  • Full-Stack Reviews: Scope and perform security reviews of web applications, APIs, and platform architectures.
  • Vulnerability Management: Triage vulnerabilities from internal testing, bug bounties, and public disclosures, providing engineers with researched remediation guidance.
  • Advocacy: Write and promote secure development practices, acting as the primary SME for engineering teams to consult on "secure-by-default" coding.

Modern Cloud Architecture Responsibilities

  • Infrastructure as Code (IaC): Use Terraform to bake security into the CI/CD pipeline, ensuring every resource is provisioned with hardened configurations.
  • Container Orchestration: Secure our Kubernetes (GKE) footprint by implementing pod security standards, network policies, and container image scanning.
  • Security Parity: Ensure consistent security controls across diverse environments, minimizing "configuration drift" through automated drift detection.
  • Innovation: Continuously evaluate emerging technologies to replace manual security routines with automated, scalable solutions.

Experience & Expertise

  • 15+ Years of progressive experience in security architecture, with at least 5 years specifically focused on cloud-native environments.
  • GCP Mastery: Deep, demonstrable experience with Google Cloud Platform and its native security suite.
  • Automation Mindset: Proven ability to write and review Terraform and manage security within Kubernetes clusters.
  • Security Frameworks: Expert knowledge of NIST, CIS Benchmarks, and ISO 27001, and how to map them to technical cloud controls.

Leadership Skills

  • Strategic Influence: Ability to define security strategy for multiple business units and influence stakeholders from DevOps to the C-Suite.
  • Communication: Skilled at translating "security-speak" into actionable business logic for non-technical partners.
  • Analytical Rigor: A proactive problem-solver who doesn't just find holes but builds the patches and the processes to prevent them.

Unleash Your Potential

When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Candidate Privacy Statement

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records. At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $218,400 - $365,200 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $263,200 - $401,400 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Key skills/competency

  • Cloud Security Architecture
  • GCP Security
  • Identity and Access Management (IAM)
  • Infrastructure as Code (IaC)
  • Container Security (Kubernetes/GKE)
  • Threat Modeling
  • Vulnerability Management
  • Security Policy Enforcement
  • Cloud-Native Security Services
  • Secure Development Practices

Tags:

Cloud Security Architect
GCP Security
Cybersecurity
Cloud Computing
Security Architecture
Infrastructure as Code
Terraform
Kubernetes Security
IAM
Threat Modeling
Vulnerability Management
NIST
CIS Benchmarks
ISO 27001
Salesforce
Software Engineering

Share Job:

How to Get Hired at Salesforce

  • Tailor your resume: Highlight GCP, IaC, and security architecture experience.
  • Showcase leadership: Emphasize strategic influence and communication skills.
  • Quantify achievements: Use data to demonstrate impact in security roles.
  • Prepare for interviews: Expect questions on cloud security principles and problem-solving.
  • Network internally: Connect with Salesforce employees for insights.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background