Business Information Security Officer; BISO
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Data Security, Information Security, IT Consultant
Business Information Security Officer (BISO)
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category:
Product
Job Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Job Title:
Business Information Security Officer (BISO)
Locations:
San Francisco, CA - Seattle, WA - Bellevue, WA
About the team
Salesforce's Product Security team, a vital part of the broader Security organization, is dedicated to securing our customer data and assets while proactively managing risk and enhancing security posture. We thrive on deep collaboration with product and engineering teams to achieve optimal risk outcomes and maintain the trust our customers place in us.
We're seeking two highly accomplished Business Information Security Officers (BISOs) to join our team, one supporting our Availability & Infrastructure Engineering (AiE) team and the other our Hyperforce Platform Services (HPS) team. You will be leading security accountability for critical areas of our infrastructure and platform. These roles require moving beyond traditional compliance to become co-owners of security outcomes.
BISO for Availability & Infrastructure Engineering (AiE)
As the BISO for AiE, you will assume accountability for the security risk posture of the teams that keep Salesforce running 24/7/365 including Site Reliability Engineering (SRE), Big Data Observability, and Global Incident Response.
Your Mission:
- Partner with AiE leadership to prioritize security risks within the context of mission-critical availability.
- Be the "Voice of Security" for operational teams where availability is intrinsically linked to security.
- Champion "Security for Operations" mindset, ensuring incident response frameworks, observability pipelines, and change management processes are robust against both adversarial threats and operational errors.
- Integrate "Security as Code" within CI/CD and release pipelines.
- Govern the use of AI in operations to automate security defenses and support operational resiliency.
BISO for Hyperforce Platform Services (HPS)
As the BISO for HPS, you will secure the foundation of our business-our "Hyperforce" architecture-operating as the "Voice of Security" embedded with our most critical engineering teams.
Your Mission:
- Partner with HPS leadership and architects to translate complex risks into engineering reality.
- Bring a "platform" mindset, understanding that security controls at the platform and infrastructure layer deliver exponential scale and value to downstream cloud tenants.
- Bridge the gap between "architectural risks" (multi-substrate security, cloud dependencies) and "operational risks" (patch management, configuration drift).
- Foster a culture where security is indistinguishable from quality.
- Ensure risk decisions are deeply informed by specific technical context, constraints, and capabilities of our systems.
Your Impact - Core Responsibilities (Both Roles)
- Security Accountability & Partnership:
Partner with product and engineering leadership to collaboratively prioritize security initiatives, negotiate trade-offs, and ensure executive-level accountability for achieving security and business outcomes. - Strategic Risk Communication:
Translate complex technical security signals into clear, compelling, and actionable executive and board-level business narratives. - Operational
Risk Management:
Deliver regular, metric-driven readouts on security risk posture, actively maintain the Security Risk Register, and lead security due diligence for remediation timelines. - Secure-by-Design/Secu…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).