To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Software Engineering
Job Details
Authentication Platform - Software Engineer (MTS)
About the team
The Authentication Platform team owns the core identity services for Salesforce's production infrastructure - the Production IAM stack. The portfolio spans Kerberos-based authentication, TOTP, and FIDO2/WebAuthn, bridging legacy infrastructure protocols and modern cloud-native identity standards. Because the platform is a tier-0 dependency for the entire company, we run at massive throughput with a 4+ nines availability target across Public Cloud (AWS/GCP) and hybrid deployments on Kubernetes, with modern CI/CD. Our security posture is Zero Trust and least-privilege by default, and we partner closely with security architects on identity verification and credential-handling design.
About the role
You'll work on services in the Production IAM stack as an individual contributor - implementing features across the Kerberos, TOTP, and FIDO2/WebAuthn service portfolio, contributing to designs that senior engineers lead, and taking on-call for a tier-0 platform. This is a hands-on engineering role focused on strong execution, growing technical depth in identity protocols, and shipping high-quality, well-tested code in a security-critical environment.
What you'll do
- Deliver features across the Authentication Platform's service portfolio - Kerberos, TOTP, FIDO2/WebAuthn - writing clean, well-tested backend code in Java, Go, or C#.
- Contribute to design specs and research spikes for features in your area, alongside more senior engineers who lead the design.
- Implement identity and federation protocols used by the platform, including Kerberos, LDAP, WebAuthn/FIDO2, and TOTP. Familiarity with SAML/OIDC is useful for interop conversations with adjacent teams.
- Partner with the Product Owner and tech lead on story-level scope, sequencing, and dependencies for your own work, and help refine and clarify work items before they land in a sprint.
- Reliably deliver as a developer, reviewer, and tester - high test coverage, clean code, and reviews that catch issues before they land, with a security-first mindset appropriate for tier-0 services.
- Apply Salesforce engineering best practices to code, tests, and CI/CD pipelines. Leave code in better shape than you found it.
- Use AI development tools (e.g.Claude Code) in your day-to-day workflow, and critically evaluate both human and AI-generated code for correctness, performance, and security compliance.
- Analyze and fix bugs in your area, working with more senior engineers on the complex ones. Debug production issues and drive them to a fix.
- Exhibit ownership beyond just coding your features - an active role in testing, review, and monitoring is part of the job, especially given the tier-0 nature of the platform.
- Participate in the on-call rotation for the Authentication Platform and handle common alerts confidently. On-call is a real, high-visibility part of this role because of the platform's tier-0 status.
- Understand the platform's telemetry - metrics, logs, traces, SLIs - and extend it for the features you own. The availability target is 4+ nines.
- Contribute to Root Cause Analyses for incidents in your area, and follow through on assigned action items.
- Work with internal stakeholders - service teams and infrastructure owners who depend on the Authentication Platform - to answer integration questions about the features you own.
- Author and maintain technical documentation and runbooks for your work.
Minimum Requirements
- Strong programming ability in Java, Go, or C#, with production experience building backend services.
- Working knowledge of at least one identity or federation protocol from this set: Kerberos, LDAP, WebAuthn/FIDO2, TOTP, SAML, OIDC. Deeper experience in one or more is a plus.
- Experience building, deploying, and debugging distributed services in a Public Cloud environment (AWS or GCP) or a hybrid deployment, using Kubernetes and modern CI/CD.
- Solid grasp of software fundamentals: data structures, testing, code review, source control, CI/CD, and Agile execution as a team member.
- A security-first mindset - writing code with least-privilege defaults, threat-aware reviews, and thorough automated testing appropriate for identity-critical systems.
- Ability to debug production issues in a distributed system using logs, metrics, and traces.
- Comfortable executing an agreed-upon plan largely independently, escalating design-level and cross-cutting decisions to senior engineers.
Preferred Requirements
- IAM specialist depth - familiarity with the internals of one or more of Kerberos, LDAP, WebAuthn/FIDO2, TOTP, and the interop story with SAML/OIDC.
- Security hardening - familiarity with HSMs, PKI, and secure credential storage patterns.
- Compliance and auditing - exposure to controls and evidence requirements under PCI, SOC 2, or HIPAA.
- Operational grit - experience on-call for a high-visibility production service, and comfort debugging live incidents under pressure.
- Experience integrating AI development tools into engineering workflows, including prompt design and reviewing AI-generated code for security-critical systems.
Education
-Master's degree (or foreign equivalent) in Computer Science, Cybersecurity, Software Engineering, or a related field. A Bachelor's degree (or foreign equivalent) is acceptable with additional years of experience.
Minimum years of experience
- 3 years of software engineering experience
Unleash Your Potential
When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future - but to redefine what's possible - for yourself, for AI, and the world.