Salesforce Apex Code Security (W2)

MRCC Solutions
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$135,200.0 - $166,400.0
Working hours
Regular working hours
Job source

Tech stack

Salesforce Object Search Language (SOSL) Software System Penetration Testing Audit Trail Static Program Analysis Code Review Cyber Security Data Security Identity and Access Management Intrusion Detection and Prevention Open Web Application Security Salesforce.Com Secure Coding
+11 more
Security Information and Event Management Apex Code Salesforce Lightning Software Security Veracode Visualforce Information Technology Apex Programming Salesforce Object Query Language (SOQL) Checkmarx Crud

Job description

Our client is seeking an experienced Security Consultant to support their Salesforce development program. The client’s engineering teams write custom functionality using Apex, and this role is responsible for identifying security vulnerabilities and coding lapses within that codebase, as well as monitoring for intrusion attempts and suspicious activity across the Salesforce environment. The ideal candidate combines strong application security / code review expertise with hands-on experience in security monitoring and intrusion detection., * Perform security-focused code reviews of custom Apex classes, triggers, and Visualforce/Lightning components to identify vulnerabilities and insecure coding practices.

  • Identify and document security lapses such as SOQL/SOSL injection, insecure sharing rule bypasses, CRUD/FLS (Field-Level Security) violations, and improper use of ‘without sharing’ contexts.
  • Review Apex code for adherence to secure coding standards (OWASP guidelines adapted for Salesforce) and Salesforce security best practices.
  • Monitor the Salesforce environment for intrusion attempts, anomalous login activity, unauthorized data access, and other security events.
  • Configure and tune security monitoring tools/alerts (e.g., Salesforce Shield, Event Monitoring, Transaction Security Policies) to detect suspicious behavior in real time.
  • Investigate security incidents and alerts, perform root-cause analysis, and recommend remediation steps to development teams.
  • Collaborate with Salesforce developers to remediate identified vulnerabilities and validate fixes prior to release.
  • Develop and maintain secure coding guidelines, checklists, and review processes for the Apex development team.
  • Support periodic security audits, penetration test coordination, and compliance reviews of the Salesforce platform.
  • Provide clear, actionable reports on findings to technical and non-technical stakeholders.

Requirements

  • Proven experience as a Security Consultant, Application Security Engineer, or similar role with a focus on code security review.
  • Hands-on experience reviewing and securing Apex code within the Salesforce platform (Apex classes, triggers, batch jobs, Lightning components).
  • Strong understanding of Salesforce security architecture, including sharing rules, profiles, permission sets, FLS, and org-wide defaults.
  • Experience with security monitoring and intrusion detection tools and practices.
  • Familiarity with Salesforce Shield (Event Monitoring, Field Audit Trail, Platform Encryption) is highly desirable.
  • Knowledge of secure coding standards and common vulnerability classes (e.g., OWASP Top 10) as applied to Apex/Salesforce.
  • Experience using static/dynamic code analysis tools (e.g., Salesforce Code Analyzer, Checkmarx, Veracode) is a plus.
  • Strong analytical and troubleshooting skills, with the ability to investigate and respond to security alerts.
  • Excellent written and verbal communication skills to convey technical findings to varied audiences.
  • Relevant certifications a plus: Salesforce Certified Platform Developer I/II, Salesforce Certified Identity and Access Management Designer, CEH, Security+, or similar., * Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience).
  • Prior experience working within an IT staffing or consulting engagement model.
  • Experience integrating security monitoring workflows with SIEM tools.

Benefits & conditions

$65 - $80 an hour - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · WWC 2022

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · WWC 2024

2:17 min

Generating modules and CRUD endpoints automatically

Maximilian Otto Maximilian Otto · WWC 2024

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

2:41 min

Dynamic application security testing during the test phase

Milecia Mcgregor · LIVE

1:59 min

Identifying repetitive boilerplate code in basic CRUD applications

Noam Honig · LIVE

Videos

See all

Related articles

See all