Director, BISO - Enterprise Security
Salesforce
- Location
- New York New York
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 498 approvals (FY2023)
- Posted
- Sep 15, 2026
Skills
About this role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Product Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. Location: NY, SF, Bellevue The Experience Salesforce's Enterprise Security organization is looking for a Director, Enterprise Security, Business Information Security Officer (BISO), also known as a Security Partner. In this role, you're accountable for the security posture of major Enterprise Business Units (BUs). You're the primary point of contact between your BU customers and the broader Security organization, personally accountable for making your customer measurably more secure over time. This is a senior technical leadership position, not a relationship-management or governance-only seat. You read the designs, understand the systems, and take positions on architecture, controls, and trade-offs, holding well-reasoned technical points of view in rooms full of engineers, architects, product leaders, and executives. You own the final calls on risk prioritization and remediation sequencing for your portfolio, and you lead a small team of Security Partner professionals. Success in this role requires deep technical fluency across cloud, identity, application, and artificial intelligence/machine learning (AI/ML) security, sound business judgment when prioritizing risk, and the ability to influence senior stakeholders across engineering, product, legal, privacy, compliance, and finance. What You'll Actually Be Doing Own the end-to-end security relationship for your assigned Business Unit (BU), serving as the primary point of contact and credible voice between BU leadership and Enterprise Security. Own the risk register for your portfolio — setting severity, prioritization, and remediation sequencing, and building resourced plans with named owners and dates. Lead security engagement on design reviews, threat models, and architecture decisions, shaping secure-by-design patterns early in the development lifecycle. Lead the customer's side of active security incidents, coordinating with the Cybersecurity Operations Center (CSOC) and executive stakeholders, while managing and developing a team of Security Partner professionals. You're Our Person If... You have 12+ years of experience in cybersecurity, IT risk, or a related discipline, including significant time in a large, complex enterprise, with prior experience as a BISO, Security Partner, or equivalent senior security leadership role. You have deep technical fluency across cloud, identity, application, and AI/ML security, with the ability to hold a substantive technical point of view in design reviews and threat models. You have a track record of prioritizing and communicating risk with executive-grade written and verbal communication, including experience representing security to CISO, CIO, GM, and Board-level audiences. You have experience managing and developing security professionals, and operating effectively under ambiguity in a fast-moving, cross-functional environment. Even Better If... You hold a CISSP, CISA, CISM, or equivalent certification. You have experience in regulated industries or product lines, such as financial services, public sector, or healthcare. You have prior experience integrating acquired entities or divestitures into enterprise security