Jobs / United States / Salesforce INC

Product Security Senior

Salesforce INC · 🇺🇸 2 Locations

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Salesforce INC paid sponsored hires in similar roles8 certified filings for “Product Security Engineer” (Information Security Analysts) in CA: $178k–$233k, median $208k. Most were filed at wage level III (50%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Last confirmed live 2 days agoWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Salesforce INC

1,544 H-1B filings certified since Oct 2025

The US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Salesforce INC →

About the role

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Product Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. The Experience Salesforce's Platform Security team protects the foundational platform our customers, partners, and developers build on, balancing deep security expertise with the agility our business depends on. We're hands-on security engineers who thrive on close collaboration with Product and Engineering across the software development lifecycle, trusted for the technical depth we bring to keep the world's #1 CRM platform secure. This role is a senior product security engineer for the platform's integration and service-connectivity layer, including events, messaging, connectors, APIs, and service-to-service pathways that move customer data across trust boundaries to other internal or external systems. It also covers the fast-growing agent and connector integrations that let external tools and models talk to the platform. You'll surface concrete security risk in ambiguous system designs, drive mitigation for root causes in the layers where they should be fixed, and keep a fast-moving Engineering org shipping safely through threat modeling, design and code reviews, and secure-by-default guidance. What You'll Actually Be Doing • Own security assurance for critical backend and integration areas, driving threat modeling and security design reviews across the platform's event and integration pathways, connectors, service-to-service connectivity, and the APIs that carry data across trust boundaries. • Secure service-to-service and connector trust boundaries, driving secure design and implementation for service-to-service authentication, external client apps, and agent and Model Context Protocol (MCP) connectors, where excessive privilege, confused-deputy risk, and secret leakage are first-class threats. • Review source code in depth (Java, plus JavaScript/TypeScript or platform-hosted code as needed) in a large codebase to validate design assumptions and discover risk in authentication, integration, and access-control flows, tracing issues back to their true root cause so fixes land at the right layer. • Partner with architects, engineers, and product owners to move findings to resolution, push secure-by-default patterns into frameworks and onboarding paths, and coach junior security engineers on secure design and threat modeling. You're Our Person If... • You have hands-on experience securing backend, integration, or service-connectivity systems, with deep expertise in API security (REST/GraphQL authentication, external exposure, rate-limiting, input validation) and secure code review. • You can threat-model a system's design to surface concrete security risk rather than enumerate a checklist, tracing issues to their technical, architectural, or organizational root cause. • You have advanced knowledge of authorization and complex permission/scope models and service-to-service authentication, plus working familiarity with delegated-authorization flows such as OAuth 2.0, OpenID Connect (OIDC), and JSON Web Tokens (JWT). • Yo

View the official posting →

Source: Employer career site (Workday) First seen: 2026-10-01 Last confirmed: 2026-10-01 How our data works → Report this job

Similar opportunities