> Markdown version of [/jobs/ext/1507229-senior-software-engineer-smts-identity-access-management-device-trust](https://www.wearedevelopers.com/jobs/ext/1507229-senior-software-engineer-smts-identity-access-management-device-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer (SMTS), Identity & Access Management - Device Trust - **Company:** Salesforce.com, Inc. - **Location:** Bellevue, WA, United States - **Experience:** Expert - **Salary:** $148,500.0 - $223,900.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Software as a Service, Cyber Security, Continuous Delivery, Continuous Integration, Linux, DevOps, Distributed Systems, Multi-Factor Authentication, Hardware Security Module, Identity and Access Management, Python (Programming Language), OAuth, OpenStack, Open Web Application Security, Platform as a Service (PAAS), Perforce, Public Key Infrastructure, Zero Trust Network Access, Swagger, Salesforce.Com, Security Assertion Markup Language (SAML), Software Construction, System Software, Openapi, Transport Layer Security, Google Cloud, Cloud Platform System, Delivery Pipeline, Git, Build Management, Containerization, Kubernetes, Infrastructure Automation Frameworks, U-Boot, Terraform, Software Version Control, Docker, Jenkins, Golang - **Published:** July 30, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17758499?backUrl=%2Fcareer%2F17758499%2FSenior-Software-Engineer-Smts-Identity-Access-Management-Device-Trust-Washington-Bellevue ## About the Role * You have 7+ years of industry experience, including at least 5+ years building distributed systems in Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS) environments, and 5+ years operating in high-availability, mission-critical environments (99.999% uptime). * You have strong experience designing and operating distributed systems on public cloud platforms (Amazon Web Services (AWS), Google Cloud Platform (GCP), or Microsoft Azure). * You are proficient in Golang and/or Python. * You have expertise in security protocols and identity frameworks: Transport Layer Security (TLS), OAuth, Security Assertion Markup Language (SAML), PKI, and certificates. * You are familiar with system patterns and Application Programming Interface (API) standards including REST and OpenAPI/Swagger. * You have solid understanding of DevOps practices, continuous integration and delivery (CI/CD), monitoring, and full ownership of production systems. * You have experience building software for Linux and/or Windows environments. * You have experience with CI/CD tools such as Jenkins, AWS CodePipeline, or AWS CodeBuild. * You have a working understanding of large-scale infrastructure-as-a-service platforms (e.g., Amazon AWS, Microsoft Azure, OpenStack). * You are familiar with source code management and version control systems (e.g., git, Perforce). * You have hands-on experience with container technologies such as Docker and Kubernetes. * You have strong communication skills and a collaborative mindset that prioritizes team success. * A related technical degree required Even Better If... * You have prior experience developing system-level features related to platform security or device attestation. * You have experience working with hardware-backed security mechanisms such as TPM, Hardware Security Module (HSM), or Secure Boot. * You are familiar with security compliance frameworks such as NIST, ISO, or SOC 2. * You have experience securing products and infrastructure against the OWASP Top 10 and/or CWE Top 25. * You have broad exposure to security disciplines and a deep understanding of models behind core security concepts such as Multi-Factor Authentication (MFA), Zero Trust, and securely managing secrets or tokens. ## Description As a software engineer on our Identity and Access Management (IAM) platform team, you work at the intersection of distributed systems and enterprise security - building the foundational services that let every Salesforce engineer operate securely, regardless of environment. This is a high-impact, high-visibility role on one of our most critical platform investments: a unified, policy-driven containment and device trust infrastructure underpinning Salesforce's Zero Trust and Cybersecurity Mesh Architecture. What You'll Actually Be Doing * Design and build scalable authentication and authorization services for distributed environments. * Develop and maintain system software for multiple operating systems (Linux, macOS, Windows). * Implement and operate large-scale security services using Golang or Python. * Integrate and extend secure device attestation mechanisms, including Trusted Platform Module (TPM)-based hardware trust. * Contribute to platform-level identity and security solutions using Public Key Infrastructure (PKI), certificates, and secure transport. * Build and manage containerized workloads with Kubernetes, Docker, and infrastructure-as-code tools like Terraform. * Operate and maintain services in a full DevOps model: monitor, troubleshoot, and continuously improve. * Work in an Agile team to deliver iteratively and collaboratively. * Partner with cross-functional teams across security, infrastructure, and engineering to ensure platform integrity and trustworthiness. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)