Software Engineer, MTS, Enterprise Security, Identity & Access Management
Job Description
Salesforce’s Enterprise Security IAM team is looking for a Software Engineer, MTS to help design, build, and operate scalable identity and access management services that span enterprise networks, cloud environments, and data centers. You’ll contribute to two focused groups, IAM Platform and Full-Stack IAM Engineering, with an emphasis on AI-enabled security engineering and a secure software development lifecycle.
Responsibilities
- Design, build, and operate scalable IAM services and APIs covering identity lifecycle, access requests, entitlement and role management, and access certifications.
- Develop Privileged Access Management capabilities including credential vaulting and rotation, session control, secrets management, and just-in-time access flows that grant elevated rights for a limited time with automatic revocation.
- Model and secure non-human identities such as service accounts, agents, workloads, and machine credentials, including issuance, rotation, and lifecycle governance.
- Develop full-stack features, backend services, and modern web front-ends delivering intuitive self-service and administrative experiences for IAM.
- Build and manage containerized workloads with Kubernetes and Docker, and use Terraform for infrastructure-as-code; operate in a full DevOps model to monitor, troubleshoot, and continuously improve.
- Integrate across identity sources, directories, and downstream applications using SCIM, REST, and event-driven patterns.
- Collaborate with governance and compliance teams to embed separation of duties, least-privilege access, and audit controls (SOX, NIST, SOC 2) into the platform.
- Write clean, secure code; participate in design and code reviews; and champion secure SDLC practices.
- Work with cross-functional teams across security, infrastructure, product, and engineering to maintain platform integrity and trust.
- Create and maintain technical documentation, runbooks, and enablement materials.
- Design significant features, mentor junior engineers, and guide technical direction and continuous improvement across the platform.
- Build and ship production-grade software using modern engineering practices, with AI as a core part of the development workflow to deliver secure, high-quality code.
- Design and orchestrate complex systems where AI agents integrate into human workflows, driving efficiency and innovation at scale.
- Contribute to a shared system context that captures designs, constraints, and standards to enable AI to operate reliably, and critically evaluate code for correctness, security, and performance.
Requirements
- 3+ years of professional software development experience building distributed systems in SaaS, PaaS, or IaaS environments.
- Full-stack proficiency with strong backend skills in Java, Go, and/or Python, plus frontend experience with modern frameworks (for example, React).
- Solid understanding of IAM domains including identity governance and lifecycle, authentication, authorization, RBAC and entitlement models, PAM including just-in-time access, and protocols such as OAuth 2.0, OIDC, SAML, SCIM, and LDAP.
- Experience designing and consuming REST APIs and integrating heterogeneous systems.
- Strong experience with public cloud platforms (AWS, Azure, and/or GCP), containers (Docker, Kubernetes), and infrastructure-as-code (Terraform).
- Hands-on experience with CI/CD and source control (Git, Jenkins or equivalent), including secure coding and defensive programming.
- Solid grasp of DevOps practices, monitoring, and owning production systems in high-availability environments.
- Strong problem-solving, debugging, communication, and collaboration skills.
- Demonstrated AI-first approach to engineering, using AI to move faster and broaden stack fluency, with experience using AI tools in development workflows (e.g., Claude Code, GitHub Copilot, Codex, Cursor, etc.).
- Advanced prompt engineering skills with the ability to craft precise prompts and shape system context for reliable, secure, production-ready AI outputs.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
Technologies
- Java, Go, Python
- React
- AWS, Azure, GCP
- Docker, Kubernetes
- Terraform
- SCIM, REST, OpenAPI/Swagger
- OAuth 2.0, OIDC, SAML
- LDAP, JSON, XML
- Git, Jenkins
- Claude Code, GitHub Copilot, Codex, Cursor
Benefits
- Time off programs
- Medical insurance
- Dental insurance
- Vision insurance
- Mental health support
- Paid parental leave
- Life insurance
- Disability insurance
- 401(k)
- Employee stock purchasing program
The Experience
The Salesforce Enterprise Security Engineering team builds scalable, fault-tolerant distributed systems that deliver cloud-scale IAM services across enterprise networks, public cloud infrastructure, and internal data centers. These teams provide the core building blocks for identity lifecycle, governance, authentication, authorization, and Privileged Access Management, enabling Salesforce engineers to operate with trusted security foundations.
Even Better If
- Experience integrating AI and agentic capabilities into IAM workflows or user experiences
- Experience working with globally distributed teams and large enterprises
- Familiarity with commercial IAM platforms such as SailPoint, Okta, CyberArk, or Active Directory/EntraID
Accommodations
If you need a reasonable accommodation during the application or recruiting process, please submit a request via the Accommodations Request Form.
Posting Statement
Salesforce is an equal opportunity employer and selects candidates based on merit, competence, and experience. In the United States, the base salary range for this role is typically US dollars 117,200 to 176,700 annually, depending on location, level, knowledge, skills, and experience. This range excludes bonuses, equity, and benefits. Salesforce offers a comprehensive benefits package including time off, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchase program.