> Markdown version of [/jobs/ext/1817035-software-security-engineer-distributed-systems-mts](https://www.wearedevelopers.com/jobs/ext/1817035-software-security-engineer-distributed-systems-mts). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Engineer (Distributed Systems) MTS - **Company:** Salesforce.com, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $117,200.0 - $223,900.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Layers, Cloud Computing, Cloud Computing Security, Computer Programming, Linux, DevOps, Distributed Systems, Monitoring of Systems, Python (Programming Language), Network Protocols, Object-Oriented Software Development, Open Source Technology, Systems Development Life Cycle, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Scripting, Software Security, Infrastructure as Code (IaC), Kubernetes, Terraform, Dynatrace, Docker, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** July 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/86203662/1 ## About the Role * Engineering Mindset: 2+ years of experience in Security Engineering with a focus on building tools, not just managing them. * Coding Proficiency: Strong experience in Go, Java, or Python with a solid grasp of Object-Oriented Programming and automation. * Cloud & Infrastructure Expertise: Deep experience with GCP (similar) and Terraform for managing cloud security posture (CSPM) and infrastructure. * Security Domain Knowledge: Practical experience with network protocols, OS hardening (Linux), and modern attack vectors. * Collaborative Spirit: A desire to work cross-functionally with DevOps to embed security into the SDLC., * Experience in secure software development lifecycle (SDLC) practices. * Familiarity with container security technologies (e.g., Docker, Kubernetes). * Experience with developing or contributing to open source tools. ## Description We are seeking a proactive and skilled Software Security Engineer to join our GCP team. The ideal candidate will be responsible for enhancing our security posture across various domains, focusing on development, vulnerability management, infrastructure security, and the security of distributed and scalable distributed systems. This role requires hands-on experience with security systems, a deep understanding of modern threats, and the ability to drive security improvements through engineering solutions. As a Software Security Engineer, you won't just find vulnerabilities, you'll engineer the systems that prevent them. You will play a pivotal role in securing our distributed micro-services architecture on GCP, moving security by building automated, high-performance tools that empower our entire engineering organization. Your Impact: * Security Engineering & Automation: Build and integrate high-performance security tools and custom scripts into our CI/CD pipelines (SAST/DAST, SCA, SIEM) to automate manual toil. * Infrastructure as Code (IaC): Develop and secure Terraform/IaC templates to ensure our cloud infrastructure is hardened by design before it ever reaches production. * Vulnerability Leadership: Lead the end-to-end vulnerability lifecycle, using a risk-based approach to prioritize remediation across network, cloud, and application layers. * Architecture & Threat Modeling: Partner with DevOps and Product teams to conduct threat modeling and architectural reviews, ensuring new features are resilient and scalable. * Compliance & Governance: Act as the technical lead for audits (SOC2, ISO 27001), leveraging automation to provide evidence of consistent monitoring and timely closure of risks. * Production Resilience: Troubleshooting and resolving complex security issues in production using distributed tracing and modern monitoring tools. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023)