Software Engineering MTS
What you'll need to apply
Fields this application requires
Company-specific questions
- Do you have the unrestricted right to work in the country to which you're applying? (You must answer “No” if you are on any visa or possess any government issued work authorization document that has an expiration date; you should answer “Yes” if you have DACA or TPS authorization in the US)
- Government Employment: In the last 5 years, have you been an employee of a U.S. federal, state, or local government, including a "special Government employee" (defined under 18 U.S.C. §202), or a member of the U.S. Armed Services (including Reserve and Guard components)?
- I attest/confirm that I have no post-government employment restrictions currently applicable to me that have not already been addressed or disclosed in the previous questions, OR that if I am aware of any applicable restrictions, I will disclose them to the recruiter if contacted for further processing of my application. If I received written advice from my current or former government employer about work restrictions that are still active, I will provide it to the recruiter if contacted for further processing of my application.
- Are you currently or have you in the past been debarred, suspended, proposed for debarment or declared ineligible for award of a contract by any federal agency?
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
Authentication Platform — Software Engineer (MTS)
About the team The Authentication Platform team owns the core identity services for Salesforce's production infrastructure — the Production IAM stack. The portfolio spans Kerberos-based authentication, TOTP, and FIDO2/WebAuthn, bridging legacy infrastructure protocols and modern cloud-native identity standards.
Because the platform is a tier-0 dependency for the entire company, we run at massive throughput with a 4+ nines availability target across Public Cloud (AWS/GCP) and hybrid deployments on Kubernetes, with modern CI/CD. Our security posture is Zero Trust and least-privilege by default, and we partner closely with security architects on identity verification and credential-handling design.
About the role
You'll work on services in the Production IAM stack as an individual contributor — implementing features across the Kerberos, TOTP, and FIDO2/WebAuthn service portfolio, contributing to designs that senior engineers lead, and taking on-call for a tier-0 platform.
This is a hands-on engineering role focused on strong execution, growing technical depth in identity protocols, and shipping high-quality, well-tested code in a security-critical environment.
What you'll do
- Deliver features across the Authentication Platform's service portfolio - Kerberos, TOTP, FIDO2/WebAuthn - writing clean, well-tested backend code in Java, Go, or C#.
- Contribute to design specs and research spikes for features in your area, alongside more senior engineers who lead the design.
- Implement identity and federation protocols used by the platform, including Kerberos, LDAP, WebAuthn/FIDO2, and TOTP. Familiarity with SAML/OIDC is useful for interop conversations with adjacent teams.
- Partner with the Product Owner and tech lead on story-level scope, sequencing, and dependencies for your own work, and help refine and clarify work items before they land in a sprint.
- Reliably deliver as a developer, reviewer, and tester — high test coverage, clean code, and reviews that catch issues before they land, with a security-first mindset appropriate for tier-0 services.
- Apply Salesforce engineering best practices to code, tests, and CI/CD pipelines. Leave code in better shape than you found it.
- Use AI development tools (e.g.Claude Code) in your day-to-day workflow, and critically evaluate both human and AI-generated code for correctness, performance, and security compliance.
- Analyze and fix bugs in your area, working with more senior engineers on the complex ones. Debug production issues and drive them to a fix.
- Exhibit ownership beyond just coding your features — an active role in testing, review, and monitoring is part of the job, especially given the tier-0 nature of the platform.
- Participate in the on-call rotation for the Authentication Platform and handle common alerts confidently. On-call is a real, high-visibility part of this role because of the platform's tier-0 status.
- Understand the platform's telemetry — metrics, logs, traces, SLIs — and extend it for the features you own. The availability target is 4+ nines.
- Contribute to Root Cause Analyses for incidents in your area, and follow through on assigned action items.
- Work with internal stakeholders — service teams and infrastructure owners who depend on the Authentication Platform — to answer integration questions about the features you own.
- Author and maintain technical documentation and runbooks for your work.
Minimum Requirements
- Strong programming ability in Java, Go, or C#, with production experience building backend services.
- Working knowledge of at least one identity or federation protocol from this set: Kerberos, LDAP, WebAuthn/FIDO2, TOTP, SAML, OIDC. Deeper experience in one or more is a plus.
- Experience building, deploying, and debugging distributed services in a Public Cloud environment (AWS or GCP) or a hybrid deployment, using Kubernetes and modern CI/CD.
- Solid grasp of software fundamentals: data structures, testing, code review, source control, CI/CD, and Agile execution as a team member.
- A security-first mindset — writing code with least-privilege defaults, threat-aware reviews, and thorough automated testing appropriate for identity-critical systems.
- Ability to debug production issues in a distributed system using logs, metrics, and traces.
- Comfortable executing an agreed-upon plan largely independently, escalating design-level and cross-cutting decisions to senior engineers.
Preferred Requirements
- IAM specialist depth — familiarity with the internals of one or more of Kerberos, LDAP, WebAuthn/FIDO2, TOTP, and the interop story with SAML/OIDC.
- Security hardening — familiarity with HSMs, PKI, and secure credential storage patterns.
- Compliance and auditing — exposure to controls and evidence requirements under PCI, SOC 2, or HIPAA.
- Operational grit — experience on-call for a high-visibility production service, and comfort debugging live incidents under pressure.
- Experience integrating AI development tools into engineering workflows, including prompt design and reviewing AI-generated code for security-critical systems.
Education
-Master's degree (or foreign equivalent) in Computer Science, Cybersecurity, Software Engineering, or a related field. A Bachelor's degree (or foreign equivalent) is acceptable with additional years of experience.
Minimum years of experience
- 3 years of software engineering experience