Software Engineering PMTS - Cloud Security - Hyderabad
What you'll need to apply
Fields this application requires
Company-specific questions
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
Come join our growing Hyperforce Enterprise Security organization. We are chartered with architecting, implementing, and operating security solutions that protect Salesforce’s complex, multi-cloud technology landscape at scale.
As a Principal Member of Technical Staff, you will provide technical leadership in building the next generation of infrastructure security and developer security guardrails. You will work across the software development and deployment lifecycle to identify security risks early, build scalable controls, and enable secure-by-default engineering practices without compromising developer velocity.
Our team operates at the intersection of cloud security, application security, infrastructure security, DevSecOps, Kubernetes, CI/CD, and runtime security. We build and operate security guardrails that identify and prevent high-risk security issues from source code and Infrastructure as Code through CI/CD and into runtime environments.
You will be expected to operate at both strategic and hands-on technical levels, defining architecture and technical direction while also diving deeply into complex engineering problems, writing production-quality code, and driving solutions from concept through deployment and operation.
This role is an opportunity to shape security capabilities that operate at significant scale across Salesforce infrastructure and to influence how security is embedded throughout the engineering lifecycle.
Responsibilities
- Act as a technical leader and subject matter expert for infrastructure security and security guardrails, providing architectural direction across teams.
- Design and build scalable shift-left security capabilities that identify security risks in source code, Infrastructure as Code, containerized workloads, and deployment configurations before they reach production.
- Architect and build shift-left security controls that identify security risks early while providing developers with actionable findings and straightforward remediation paths.
- Design scalable policy-as-code and security enforcement frameworks for consistent security controls across multiple gates and environments.
- Drive risk-based security engineering by identifying exploitable, high-impact, and meaningful security risks rather than treating all scanner findings equally.
- Design mechanisms for security finding correlation, prioritization, deduplication, and enforcement when signals originate from multiple security systems.
- Lead architecture and implementation of Kubernetes admission control and workload security capabilities.
- Define technical strategies for reliability, scalability, performance, observability, fault tolerance, and operational readiness of security services.
- Establish and evolve SLIs, SLOs, telemetry, rollout strategies, and operational practices for critical security services.
- Own technical outcomes across the complete lifecycle — requirements, architecture, implementation, testing, deployment, production readiness, rollout, and ongoing operations.
- Continuously identify opportunities to improve security coverage, automation, detection quality, enforcement, and developer experience.
- Establish engineering standards and best practices for reliability, scalability, observability, testing, and operational readiness of security services.
- Mentor senior engineers and raise the technical bar across the organization.
- Influence technical strategy and roadmap decisions across teams and drive initiatives from concept through production.
- Build and ship high-quality, production-grade software using modern engineering practices, with AI as a core part of your development workflow by pushing the boundaries of AI development tools to deliver secure, optimized, and high-quality code.
- Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation at scale.
- Contribute to building and maintaining the shared system context, an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably.
- Critically evaluate code (human or AI-generated) for correctness, quality, security, and performance.
Basic Qualifications
- Bachelor's degree in Computer Science, a related technical field involving software/systems engineering, or equivalent practical experience.
- 15+ years of software engineering, systems engineering, security engineering with significant experience designing and delivering large-scale production systems.
- Strong programming experience in one or more languages such as Go, Java, or Python, with the ability to design, implement, debug, and review production-quality systems.
- Deep understanding of cloud infrastructure and cloud security, including experience with AWS, GCP, or Azure.
- Strong hands-on experience with Kubernetes, containers, and cloud-native infrastructure.
- Strong understanding of CI/CD architecture and DevSecOps, including deployment pipelines, security gates, policy enforcement, and automation.
- Proven experience with Infrastructure as Code, such as Terraform, Helm, CloudFormation, or equivalent technologies.
- Experience designing distributed, highly scalable, reliable, and secure systems.
- Strong understanding of security engineering concepts including vulnerability management, configuration security, policy enforcement, workload security, identity/access controls, and risk assessment.
- Demonstrated ability to take ambiguous security problems, identify the core technical challenge, and drive an architecture and implementation to completion.
- Strong written and verbal communication skills, including the ability to explain complex architectures and trade-offs to senior technical and business audiences.
- Preferred Qualifications
- Deep experience in cloud-native security, DevSecOps, infrastructure security, or application security.
- Experience building security platforms/services or guardrails that operate at large enterprise scale.
- Experience with Kubernetes Admission Controllers, admission policies, OPA/Gatekeeper, Kyverno, or similar policy enforcement technologies.
- Experience with policy-as-code and security-as-code frameworks.
- Experience with IaC security and tools such as Checkov, OPA, Terraform security scanning, or equivalent technologies.
- Strong understanding of container and workload security, including Seccomp, Linux security mechanisms, container isolation, and runtime security.
- Experience building systems that correlate security signals from multiple sources and prioritize findings based on risk, exploitability, exposure, and business impact.
- Experience with vulnerability management, cloud security posture management, container security, or automated security remediation.
- Experience designing developer-facing security products with a strong focus on actionable findings, low friction remediation, and developer experience.
- Experience designing security controls across the complete lifecycle: source → IaC → CI/CD → deployment → admission → runtime.
- Strong understanding of cloud networking, identity, workload architecture, and distributed systems.
- Experience driving technical strategy across multiple engineering organizations.
- Demonstrated ability to identify new security opportunities and turn them into scalable engineering solutions.
- Experience mentoring senior engineers and serving as a technical leader for complex, multi-team initiatives.
- A demonstrated, genuine AI-first approach to engineering — using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty.
- Experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor, etc.) in development workflows.
- Advanced prompt engineering skills and the ability to write precise, structured prompts and cultivate the system context that makes AI outputs reliable, secure, and product