Software Engineering SMTS, Identity and Access Management
What you'll need to apply
Fields this application requires
Company-specific questions
- As a U.S. company that exports software and technology internationally, we must comply with U.S. export control laws in every country where we operate. The information provided will be used to determine whether we need to obtain an Export Control License for your employment if you are hired. Are you a citizen, national or permanent resident of Iran, Cuba, North Korea or Syria?
- Regarding future positions at Salesforce, please select one of the following options
- I acknowledge that I have read, reviewed and answered the above questions truthfully and accurately. I further understand, and agree, that any offer of employment I may receive from Salesforce is conditional on the truth of the above statements and that, in the event it is subsequently determined that any of the above is inaccurate, any such offer of employment can be rescinded and, in the event I have commenced employment, such employment will be terminated, to the extent permitted by applicable law. Please select "yes" if you acknowledge.
About this role
Employer-provided description, formatted for easier reading.
Software Engineering SMTS, Identity & Access Management
About the team The Salesforce Enterprise Security Engineering team builds and operates highly scalable, fault-tolerant, distributed systems that deliver cloud-scale Identity and Access Management (IAM) services across our Enterprise network, public cloud infrastructure, and internal data centers.
We provide the core building blocks for identity lifecycle, governance, authentication, authorization and privileged access management that protect customer trust and empower every Salesforce engineer to operate securely, regardless of environment.
We are seeking a full-stack software engineer with a track record of building modern, secure services and applications following the Software Development Life Cycle and best security development practices. You'll work across the IAM domain, so a solid understanding of identity concepts in the authentication, authorization, and identity governance space is important for this role.
About the position This is a hands-on software engineering role with a focus on the IAM domain. You will design and build end-to-end capabilities from backend services and APIs to the user-facing experiences that power identity lifecycle (human/non-human), access requests, provisioning, entitlement/role management, access certifications, and policy-driven access decisions at enterprise scale.
You will secure the emerging agentic enterprise by designing controls for AI agents and autonomous workloads, including agent identity, privilege, least privilege, just-in-time access, time-bound access, separation of duties, and continuous risk-based access decisions.
You will also own features through the full development lifecycle: design, implementation, testing, deployment, and continuous improvement. You'll partner across application owners, product management, and governance to translate identity and compliance requirements into intuitive, reliable, and scalable solutions.
This work is foundational to advancing Salesforce's Zero Trust architecture, enabling dynamic, real-time access decisions based on employment status, role change, and device or user trust.
Responsibilities
- Design, build, and operate scalable IAM services and APIs spanning identity lifecycle, access requests, entitlement/role management and access certifications.
- Build privileged access management (PAM) capabilities — credential vaulting/rotation, session control, and secrets management and just-in-time (JIT) access flows that grant elevated, time-bound entitlements and revoke them automatically.
- Model and secure non-human/workload identities (NHI) — service accounts, agents, workloads, and machine credentials — including issuance, rotation, and lifecycle governance.
- Develop full-stack features, backend services and modern web front-ends that deliver intuitive self-service and administrative experiences for IAM.
- Build and manage containerized workloads with Kubernetes, Docker, and infrastructure-as-code (Terraform); operate services in a full DevOps model (monitor, troubleshoot, continuously improve).
- Integrate across identity sources, directories, and downstream applications using SCIM, REST, and event-driven patterns.
- Partner with governance and compliance teams to embed SoD, least-privilege, and audit controls (SOX, NIST, SOC 2) into the platform.
- Write clean, maintainable, secure code; participate in design and code reviews; and champion secure SDLC practices.
- Collaborate with cross-functional teams across security, infrastructure, product, and engineering to ensure platform integrity and trustworthiness.
- Create and maintain technical documentation, runbooks, and enablement materials.
- Design for significant features, mentor junior engineers, and drive technical direction and continuous improvement across the platform.
- Required Skills/Experience SMTS: 5+ years of professional software development experience building distributed systems in SaaS, PaaS, or IaaS environments.
- Full-stack development proficiency: strong backend skills in Java, Go, and/or Python, plus front-end experience with modern frameworks (e.
- g.
- , React).
- Solid understanding of the IAM domain, identity governance/lifecycle, authentication, authorization, RBAC/entitlement models, privileged access management including just-in-time access and common protocols (OAuth2, OIDC, SAML, SCIM, LDAP).
- Experience designing and consuming REST APIs (JSON/XML, OpenAPI/Swagger) and integrating heterogeneous systems.
- Strong experience on public cloud platforms (AWS/Azure/GCP), including containers (Docker, Kubernetes) and infrastructure-as-code (Terraform).
- Hands-on experience with CI/CD and source control (Git, Jenkins, or equivalent), including secure coding and defensive programming.
- Solid grasp of DevOps practices, monitoring, and ownership of production systems in high-availability environments.
- Strong problem-solving, debugging, communication, and collaboration skills.
- Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
Preferred Qualifications
- Experience integrating AI/agentic capabilities into IAM workflows or user experiences.
- Experience with globally distributed teams and large enterprises.
- Familiarity with commercial IAM platforms (e.
- g.
- , SailPoint, Okta, CyberArk, Active Directory/EntraID) as a consumer or integrator, not required as a specialty.
- Posting Statement Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment.
- What does that mean exactly?
- It means that at Salesforce, we believe in equality for all.
- And we believe we can lead the path to equality in part by creating a workplace that's inclusive, and free from discrimination.
- Know your rights: workplace discrimination is illegal.
- Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law.
- This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey.
- It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between.
- Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit.
- The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.