OverviewWe are seeking a Salesforce Security Engineer to serve as the primary point of contact for security across the Salesforce environment. In this role, you will help strengthen the security posture and reduce security risk across the environment, address security issues and questions raised by internal and external teams, assist Information System Security Officers (ISSOs) in securing their applications, gather security artifacts to support Authorization to Operate (ATO) activities, and build Splunk queries to identify anomalous events.
Contributions
Responsibilities include:
- Design, implement, and audit Salesforce access controls (e.g., profiles, permission sets, roles, sharing rules, field-level security), applying least privilege principles across all user populations.
- Conduct periodic access reviews and recertifications to identify and remediate overly permissive or outdated access.
- Configure and maintain Salesforce security settings via the Setup Menu, including but not limited to session settings, login IP ranges/restrictions, password policies, multi-factor authentication (MFA) enforcement, Health Check, Shield Platform Encryption, and Event Monitoring.
- Build and maintain Splunk queries and dashboards to monitor Salesforce login events, permission changes, and anomalous access patterns, and support incident investigations with log analysis.
- Assess and harden web application security for Salesforce Connected Apps, including internet-facing security settings (Cross-Origin Resource Sharing (CORS), Content Security Policy (CSP), Trusted URLs, OAuth/Connected App policies, session security).
- Assist ISSOs in securing their applications and collecting security artifacts in support of their assessment and authorization efforts.
- Partner with system owners and compliance teams to ensure security configurations align with federal security requirements (e.g., NIST 800-53, FedRAMP, as applicable).
- Document security configurations, findings, and remediation steps for audit and ATO support.
- Review and provision privileged user access.
Qualifications
Required
- Ability to obtain and maintain a U.S. Government security clearance.
- Bachelor’s degree.
- 8–10 years of experience in Salesforce administration or security engineering.
- Strong knowledge of Salesforce access control models (profiles, permission sets, roles, sharing rules) and least privilege implementation.
- Extensive experience with Salesforce Setup Menu security configuration (session security, login policies, Health Check, Event Monitoring, Shield).
- Proficient in writing Splunk search queries (SPL) for log analysis, monitoring, and alerting.
- Working knowledge of web application security concepts, including internet security settings (CSP, CORS, trusted domains, OAuth flows).
Preferred
- Salesforce Administrator (ADM 201) or Salesforce security-related certification.
- One of the following security certifications: CISSP, CISM, or similar.
- Familiarity with NIST 800-53 security controls.
- Experience supporting federal government clients or ATO processes.