Senior Software Engineer (SMTS), Identity & Access Management - Device Trust
What you'll need to apply
Fields this application requires
Company-specific questions
- Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
- Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
- I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
- Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
The Salesforce Enterprise Security Engineering team designs and operates highly scalable, fault-tolerant distributed systems that deliver cloud-scale security software across multiple public cloud platforms and Salesforce's internal infrastructure. We provide the core building blocks that protect customer trust in Salesforce's products and services.
As a software engineer on our Identity and Access Management (IAM) platform team, you work at the intersection of distributed systems and enterprise security — building the foundational services that let every Salesforce engineer operate securely, regardless of environment.
This is a high-impact, high-visibility role on one of our most critical platform investments: a unified, policy-driven containment and device trust infrastructure underpinning Salesforce's Zero Trust and Cybersecurity Mesh Architecture.
What You'll Actually Be Doing
- Design and build scalable authentication and authorization services for distributed environments.
- Develop and maintain system software for multiple operating systems (Linux, macOS, Windows).
- Implement and operate large-scale security services using Golang or Python.
- Integrate and extend secure device attestation mechanisms, including Trusted Platform Module (TPM)-based hardware trust.
- Contribute to platform-level identity and security solutions using Public Key Infrastructure (PKI), certificates, and secure transport.
- Build and manage containerized workloads with Kubernetes, Docker, and infrastructure-as-code tools like Terraform.
- Operate and maintain services in a full DevOps model: monitor, troubleshoot, and continuously improve.
- Work in an Agile team to deliver iteratively and collaboratively.
- Partner with cross-functional teams across security, infrastructure, and engineering to ensure platform integrity and trustworthiness.
You're Our Person If...
- You have 7+ years of industry experience, including at least 5+ years building distributed systems in Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS) environments, and 5+ years operating in high-availability, mission-critical environments (99.999% uptime).
- You have strong experience designing and operating distributed systems on public cloud platforms (Amazon Web Services (AWS), Google Cloud Platform (GCP), or Microsoft Azure).
- You are proficient in Golang and/or Python.
- You have expertise in security protocols and identity frameworks: Transport Layer Security (TLS), OAuth, Security Assertion Markup Language (SAML), PKI, and certificates.
- You are familiar with system patterns and Application Programming Interface (API) standards including REST and OpenAPI/Swagger.
- You have solid understanding of DevOps practices, continuous integration and delivery (CI/CD), monitoring, and full ownership of production systems.
- You have experience building software for Linux and/or Windows environments.
- You have experience with CI/CD tools such as Jenkins, AWS CodePipeline, or AWS CodeBuild.
- You have a working understanding of large-scale infrastructure-as-a-service platforms (e.g., Amazon AWS, Microsoft Azure, OpenStack).
- You are familiar with source code management and version control systems (e.g., git, Perforce).
- You have hands-on experience with container technologies such as Docker and Kubernetes.
- You have strong communication skills and a collaborative mindset that prioritizes team success.
- A related technical degree required
Even Better If...
- You have prior experience developing system-level features related to platform security or device attestation.
- You have experience working with hardware-backed security mechanisms such as TPM, Hardware Security Module (HSM), or Secure Boot.
- You are familiar with security compliance frameworks such as NIST, ISO, or SOC 2.
- You have experience securing products and infrastructure against the OWASP Top 10 and/or CWE Top 25.
- You have broad exposure to security disciplines and a deep understanding of models behind core security concepts such as Multi-Factor Authentication (MFA), Zero Trust, and securely managing secrets or tokens.