Software Engineer (MTS), Frontier Strike (EntSecTech)
Job Description
In this onsite Software Engineer role within Salesforce’s Enterprise Security Technology (EntSecTech), you’ll help build and run an autonomous AI red-teaming platform called Harness Orchestrator. Frontier Strike continuously tests Salesforce identity and AI-integrated systems in ways intended to mirror real attacker behavior, and your work will focus on secure orchestration, policy enforcement, and safe execution of adversarial test suites.
You’ll design production-grade systems that coordinate containerized test workloads, implement strict access controls and secrets isolation, and ensure the findings pipeline remains reliable as tests scale from lower-risk environments toward production.
What you’ll do
- Design and extend Go microservices that orchestrate multi-container test suites, including primary and utility containers, shared ephemeral volumes, and lifecycle synchronization to onboard new attack and test techniques as repeatable automated suites.
- Build policy-based sidecar gateways that mediate every test suite’s access to its target system across mocked, staging, and production, enforcing least-privilege and blast-radius limits as risk tiers increase.
- Implement pipeline stages to dedupe, suppress noise, and auto-escalate critical findings (injection, server-side request forgery (SSRF), privilege escalation, data exfiltration) so only real signal reaches the persistent findings store.
- Design per-test-suite secrets isolation using a dedicated vault, pod, and service account per suite, along with automated credential rotation to prevent a compromised suite from reaching other suites’ credentials.
- Deploy and operate containerized workloads on Kubernetes using Helm and Terraform on Amazon Web Services (AWS), where individual test run cost can vary based on suite complexity.
- Integrate with internal large language model (LLM) gateway services to track token usage and cost per scan, and build throttling and authorization controls for expensive test executions.
- Implement RBAC, network sandboxing, and geofencing so automated red-teaming can be extended safely from test environments to production.
- Monitor and troubleshoot distributed components, protecting findings-pipeline data integrity and catching misconfigurations early.
- Build and ship high-quality production software using modern engineering practices, treating AI as a core part of the development workflow to deliver secure, optimized, high-quality code.
- Help design and orchestrate complex systems where AI agents integrate into human workflows to drive efficiency and innovation at scale.
- Contribute to shared system context, an explicit repository of system designs, constraints, and standards that helps AI operate accurately and reliably.
- Critically evaluate code, whether human- or AI-generated, for correctness, quality, security, and performance.
Experience and qualifications
- 2 to 4 years of professional software development experience.
- Proficiency in Go; experience with Python or Java is also acceptable.
- Experience with distributed systems, microservices, and REST or gRPC APIs.
- Familiarity with Kubernetes, Docker, Helm, and Terraform in a cloud environment (AWS preferred).
- Understanding of software security fundamentals, including OWASP Top 10, least privilege, and secrets management.
- Strong problem-solving and debugging skills in distributed, containerized systems.
- Ability to work in a large-scale enterprise environment with production-safety constraints.
- An AI-first approach to engineering, using AI to move faster and build fluency across the stack.
- Experience using AI tools such as Claude Code, GitHub Copilot, Codex, or Cursor.
- Advanced prompt engineering skills, including writing precise, structured prompts and cultivating system context for secure, production-ready outputs.
- Bachelor’s degree in Computer Science, Software Engineering, or a related field, or equivalent experience.
Compensation: USD 117,200 to 176,700 per year.
Technologies you may work with
- Go, Python, Java, REST, gRPC
- Kubernetes, Docker, Helm, Terraform
- Amazon Web Services (AWS)
- Large language model (LLM) gateway services
- RBAC, OWASP Top 10, secrets management
- Claude Code, GitHub Copilot, Codex, Cursor
- HashiCorp Vault, cloud key management services (KMS), Open Policy Agent (OPA), mTLS, IAM
- NIST, ISO, SOC 2
Role context
- Frontier Strike, part of EntSecTech, builds and operates the Harness Orchestrator, an autonomous AI red-teaming platform that continuously tests identity and AI-integrated systems.
- This role focuses on the orchestration engine, policy gateways, and secrets-isolation systems that enable safe automated adversarial testing targeting production.
- AI plays a core role in the development workflow alongside hands-on distributed-systems engineering.
Even better if…
- Experience with policy engines (for example, Open Policy Agent (OPA)) or other fine-grained authorization frameworks.
- Exposure to AI/LLM security, adversarial testing, or red-teaming.
- Experience with secrets vault technologies (HashiCorp Vault, cloud key management services (KMS), etc.).
- Familiarity with sidecar proxy or gateway patterns and mutual Transport Layer Security (mTLS).
- Experience with identity and access management (IAM), cybersecurity, or compliance frameworks (NIST, ISO, SOC 2).
Location: Bellevue, WA (onsite).
If you need a reasonable accommodation during the application or recruiting process, submit a request via the Accommodations Request Form.