Federal Compliance & Security Architect

Salesforce · Virginia - Washington DC Metro - Remote · Atlanta · Chicago · Dallas · Denver · Herndon · Indianapolis · New York · Remote · San Francisco · Seattle

Spotted 15h agoFull time

What you'll need to apply

Fields this application requires

NameEmailPhoneCountryRésuméWork authorization answerVisa sponsorship answer

Company-specific questions

  • Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
  • Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
  • I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
  • Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
  • As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
  • Regarding future positions at Salesforce, please select one of the following options
  • I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
Job description

About this role

Employer-provided description, formatted for easier reading.

The Experience:

We are seeking a Principal Federal Compliance & Security Architect to serve as the chief technical authority for our federal platform footprint.

In this role, you will define and inform technical vision and bridge high-level compliance directives with robust cloud engineering to achieve and maintain Federal Risk and Authorization Management Program (FedRAMP) Moderate, High, and Department of Defense (DoD) Impact Level 5 (IL5) authorizations.

You will partner with the Engineering team to drive systemic engineering excellence, align cross-functional initiatives with long-range strategic goals, and act as a trusted advisor to executive leadership, key customers, and federal authorizing bodies.

The incumbent will have deep experience in Federal security and compliance requirements and focus on identifying and risks and mitigation strategies to deploy secure and compliant products.

What You'll Actually Be Doing

Architectural Leadership & Platform Strategy:

  • Partner with Engineering and Product leadership to establish architectural standards, ensure technical quality, and design highly available, resilient federal platforms capable of achieving Federal Risk and Authorization Management Program (FedRAMP) High and Department of Defense (DoD) Impact Level 5 (IL5) authorizations.
  • Evaluate technical feasibility for complex architecture initiatives, perform architectural governance reviews to ensure enterprise-wide alignment with a focus in proactive risk identification and mitigation strategy development and implementation.
  • Establish strategic architectural principles and reusable design frameworks that empower engineering teams with compliant-by-default guidance rather than prescriptive constraints.
  • Explore emerging technologies, cloud design patterns, and open-source innovations, quantifying trade-offs between delivery velocity, risk profile, and federal compliance mandates.

Federal Security & Compliance Engineering:

  • Translate National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 controls, Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG), and Federal Information Processing Standards (FIPS) requirements into scalable, high-performance cloud architectures across Amazon Web Services (AWS) GovCloud, Microsoft Azure Government, or dedicated enclaves.
  • Drive end-to-end accountability for compliance and security architecture across the platform lifecycle, proactively closing structural gaps in technical and security requirements.
  • Advance engineering excellence by defining standardized frameworks, refining Continuous Monitoring (ConMon) practices, and optimizing developer productivity.
  • Author high-impact architecture specifications, System Security Plans (SSPs), and portfolio strategy documents tailored for executive, technical, and regulatory audiences.

Operational Excellence & Delivery:

  • Conduct rigorous architecture and code reviews, drive Root-Cause Analyses (RCAs) to permanent resolution, and ensure alignment across technical deliverables and organizational goals.
  • Partner with Product Management on Long-Range Planning (LRP), leveraging data-driven insights to align release trajectories with strategic federal platform vision.
  • Monitor execution risk, optimize continuous delivery feedback loops, resolve operational friction, and balance strategic business mandates with technical trade-offs.
  • Evangelize incremental delivery models and maintain refined engineering backlogs that balance continuous compliance posture with rapid technical innovation.
  • Analyze service health metrics, advocate for true service ownership across engineering teams, and systematically identify and remediate long-term technical debt.

Stakeholder Engagement & Leadership:

  • Engage directly with key senior leaders, internal and external customers to align custom requirements, platform strategy with market trends, and champion customer needs and learnings internally.
  • Advise executive leadership on strategic architectural choices while serving as the primary technical liaison to Third-Party Assessment Organizations (3PAOs), sponsoring agencies, and Authorizing Officials (AOs).
  • Oversee cross-product technical alignment, guide platform consumption models, and ensure seamless, secure transitions into production federal environments.
  • Articulate complex security and architectural concepts to executive and customer leadership through tailored messaging, active listening, and concise presentation.
  • Coach and mentor architects and engineering leaders in soft skills, business acumen, and systemic problem-solving to build organizational capability.

You're Our Person If:

  • 12+ years of experience in security architecture, cloud engineering, or systems design, with 5+ years leading major federal compliance initiatives (Federal Risk and Authorization Management Program [FedRAMP] Moderate/High, Department of Defense [DoD] Impact Level 5 [IL5]).
  • Proven track record operating as a Principal Architect, driving cross-organizational alignment, technical strategy, and multi-year roadmaps across engineering organizations.
  • Deep technical mastery of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, NIST SP 800-37 Risk Management Framework (RMF), Federal Information Processing Standards (FIPS) 140-2/140-3, and Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG) requirements.
  • Hands-on experience designing and securing cloud architectures within Amazon Web Services (AWS) GovCloud, Microsoft Azure Government, or equivalent federal environments.
  • Direct experience acting as a technical lead through Third-Party Assessment Organization (3PAO) assessments, agency sponsorship, and Federal Risk and Authorization Management Program Program Management Office (FedRAMP PMO) / Department of Defense Authorizing Official (DoD AO) authorization cycles.
  • Exceptional written and verbal communication skills, with demonstrated ability to present complex technical topics to C-level executives and federal officials.
  • Relevant certifications preferred (e.g., Certified Information Systems Security Professional [CISSP], Certified Cloud Security Professional [CCSP], Certified Information Security Manager [CISM]).

Even Better If:

  • Active or eligible-for United States federal security clearance (Secret or Top Secret) preferred.

LI-Y*

Interested in this role?Continue on Salesforce's careers page.
Apply on Salesforce