> Markdown version of [/jobs/ext/1174228-salesforce-apex-code-security-w2](https://www.wearedevelopers.com/jobs/ext/1174228-salesforce-apex-code-security-w2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Salesforce Apex Code Security (W2) - **Company:** MRCC Solutions - **Location:** United States (Remote available) - **Salary:** $135,200.0 - $166,400.0 - **Contract:** Permanent contract - **Skills:** Salesforce Object Search Language (SOSL), Software System Penetration Testing, Audit Trail, Static Program Analysis, Code Review, Cyber Security, Data Security, Identity and Access Management, Intrusion Detection and Prevention, Open Web Application Security, Salesforce.Com, Secure Coding, Security Information and Event Management, Apex Code, Salesforce Lightning, Software Security, Veracode, Visualforce, Information Technology, Apex Programming, Salesforce Object Query Language (SOQL), Checkmarx, Crud - **Published:** July 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b59ee36cf93c38c8 ## About the Role * Proven experience as a Security Consultant, Application Security Engineer, or similar role with a focus on code security review. * Hands-on experience reviewing and securing Apex code within the Salesforce platform (Apex classes, triggers, batch jobs, Lightning components). * Strong understanding of Salesforce security architecture, including sharing rules, profiles, permission sets, FLS, and org-wide defaults. * Experience with security monitoring and intrusion detection tools and practices. * Familiarity with Salesforce Shield (Event Monitoring, Field Audit Trail, Platform Encryption) is highly desirable. * Knowledge of secure coding standards and common vulnerability classes (e.g., OWASP Top 10) as applied to Apex/Salesforce. * Experience using static/dynamic code analysis tools (e.g., Salesforce Code Analyzer, Checkmarx, Veracode) is a plus. * Strong analytical and troubleshooting skills, with the ability to investigate and respond to security alerts. * Excellent written and verbal communication skills to convey technical findings to varied audiences. * Relevant certifications a plus: Salesforce Certified Platform Developer I/II, Salesforce Certified Identity and Access Management Designer, CEH, Security+, or similar., * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent practical experience). * Prior experience working within an IT staffing or consulting engagement model. * Experience integrating security monitoring workflows with SIEM tools. ## Description Our client is seeking an experienced Security Consultant to support their Salesforce development program. The client's engineering teams write custom functionality using Apex, and this role is responsible for identifying security vulnerabilities and coding lapses within that codebase, as well as monitoring for intrusion attempts and suspicious activity across the Salesforce environment. The ideal candidate combines strong application security / code review expertise with hands-on experience in security monitoring and intrusion detection., * Perform security-focused code reviews of custom Apex classes, triggers, and Visualforce/Lightning components to identify vulnerabilities and insecure coding practices. * Identify and document security lapses such as SOQL/SOSL injection, insecure sharing rule bypasses, CRUD/FLS (Field-Level Security) violations, and improper use of 'without sharing' contexts. * Review Apex code for adherence to secure coding standards (OWASP guidelines adapted for Salesforce) and Salesforce security best practices. * Monitor the Salesforce environment for intrusion attempts, anomalous login activity, unauthorized data access, and other security events. * Configure and tune security monitoring tools/alerts (e.g., Salesforce Shield, Event Monitoring, Transaction Security Policies) to detect suspicious behavior in real time. * Investigate security incidents and alerts, perform root-cause analysis, and recommend remediation steps to development teams. * Collaborate with Salesforce developers to remediate identified vulnerabilities and validate fixes prior to release. * Develop and maintain secure coding guidelines, checklists, and review processes for the Apex development team. * Support periodic security audits, penetration test coordination, and compliance reviews of the Salesforce platform. * Provide clear, actionable reports on findings to technical and non-technical stakeholders. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Meet Your New BFF: Backend to Frontend without the Duct Tape](https://www.wearedevelopers.com/videos/682-meet-your-new-bff-backend-to-frontend-without-the-duct-tape) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [REST In Peace: Why LLMs Can't CRUD](https://www.wearedevelopers.com/videos/100272-rest-in-peace-why-llms-can-t-crud) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)