Software Engineer (MTS), Frontier Strike (EntSecTech)
What you'll need to apply
Fields this application requires
Company-specific questions
- Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
- Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
- I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
- Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
The Experience
Frontier Strike, part of Enterprise Security Technology (EntSecTech), builds and operates the Harness Orchestrator, an autonomous AI red-teaming platform that continuously tests our own identity and AI-integrated systems the way a real attacker would. This role builds the orchestration engine, policy gateways, and secrets-isolation systems that let the team safely point automated adversarial testing at production.
AI serves as a core part of the development workflow here, pairing hands-on distributed-systems engineering with modern AI-assisted tooling to ship secure, production-grade code faster.
What You'll Actually Be Doing
- Design and extend Go microservices that orchestrate multi-container test suites (primary and utility containers, shared ephemeral volumes, lifecycle synchronization) so new attack and test techniques can be onboarded as repeatable, automated suites.
- Build policy-based sidecar gateways that mediate every test suite's access to its target system, whether mocked, staging, or production, enforcing least-privilege and blast-radius limits as tests move up the risk tiers.
- Implement pipeline stages that dedupe, suppress noise, and auto-escalate critical findings (injection, server-side request forgery (SSRF), privilege escalation, data exfiltration) so only real signal reaches the persistent findings store.
- Design per-test-suite secrets isolation (dedicated vault, pod, and service account per suite) with automated credential rotation, so a compromised or misbehaving test suite can't reach another suite's credentials.
- Deploy and operate containerized workloads on Kubernetes via Helm and Terraform on Amazon Web Services (AWS), at a scale where individual test runs can cost significantly more or less depending on suite complexity.
- Integrate with internal large language model (LLM) gateway services to track token usage and cost per scan, and build throttling and authorization controls for expensive test executions.
- Implement role-based access control (RBAC), network sandboxing, and geofencing so automated red-teaming can be safely extended from test environments to production.
- Monitor and troubleshoot the platform's distributed components, ensuring findings-pipeline data integrity and proactively catching misconfigurations before they become production incidents.
- Build and ship high-quality, production-grade software using modern engineering practices, with AI as a core part of your development workflow, pushing the boundaries of AI development tools to deliver secure, optimized, and high-quality code.
- Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation at scale.
- Contribute to building and maintaining shared system context, an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably. Critically evaluate code, whether human- or AI-generated, for correctness, quality, security, and performance.
You're Our Person If...
- 2 - 4 years of professional software development experience.
- Demonstrates proficiency in Go; experience with Python or Java is also acceptable.
- Has experience with distributed systems, microservices, and Representational State Transfer (REST) or gRPC application programming interfaces (APIs).
- Is familiar with Kubernetes, Docker, Helm, and Terraform in a cloud environment, AWS preferred.
- Understands software security fundamentals: the OWASP Top 10, least privilege, and secrets management.
- Shows strong problem-solving and debugging skills in distributed, containerized systems.
- Works comfortably in a large-scale enterprise environment with production-safety constraints.
- Takes a demonstrated, genuine AI-first approach to engineering, using AI to move faster, build fluency across the stack, and contribute well beyond a core specialty.
- Has experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor) in development workflows.
- Applies advanced prompt engineering skills, writing precise, structured prompts and cultivating the system context that makes AI outputs reliable, secure, and production-ready.
- A Bachelor's degree in Computer Science, Software Engineering, or a related field, or equivalent experience.
Even Better If...
- Experience with policy engines (e.g., Open Policy Agent (OPA)) or other fine-grained authorization frameworks.
- Exposure to AI/LLM security, adversarial testing, or red-teaming.
- Experience with secrets vault technologies (HashiCorp Vault, cloud key management services (KMS), etc.).
- Familiarity with sidecar proxy/gateway patterns and mutual Transport Layer Security (mTLS).
- Experience with identity and access management (IAM), cybersecurity, or compliance frameworks (NIST, ISO, SOC 2).