Software Engineering MTS

Salesforce Inc.
Bellevue, WA, United States
3 days ago
Apply on salesforce.wd12.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$117,200.0 - $176,700.0
Working hours
Regular working hours

Tech stack

Clean Code Principles Java (Programming Language) Agile Methodology Artificial Intelligence Amazon Web Services User Authentication Automation of Tests C Sharp (Programming Language) Cloud Engineering Code Coverage Code Review Cyber Security
+20 more
Computer Programming Continuous Integration Data Structures Software Debugging Distributed Systems Identity and Access Management Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OpenID Public Key Infrastructure Zero Trust Network Access Salesforce.Com Security Assertion Markup Language (SAML) Software Engineering Prompt Engineering Backend Kubernetes Information Technology Software Coding Software Version Control

Job description

The Authentication Platform team owns the core identity services for Salesforce’s production infrastructure - the Production IAM stack. The portfolio spans Kerberos-based authentication, TOTP, and FIDO2/WebAuthn, bridging legacy infrastructure protocols and modern cloud-native identity standards. Because the platform is a tier-0 dependency for the entire company, we run at massive throughput with a 4+ nines availability target across Public Cloud (AWS/GCP) and hybrid deployments on Kubernetes, with modern CI/CD. Our security posture is Zero Trust and least-privilege by default, and we partner closely with security architects on identity verification and credential-handling design.

About the role You’ll work on services in the Production IAM stack as an individual contributor - implementing features across the Kerberos, TOTP, and FIDO2/WebAuthn service portfolio, contributing to designs that senior engineers lead, and taking on-call for a tier-0 platform. This is a hands-on engineering role focused on strong execution, growing technical depth in identity protocols, and shipping high-quality, well-tested code in a security-critical environment.

What you’ll do

  • Deliver features across the Authentication Platform’s service portfolio - Kerberos, TOTP, FIDO2/WebAuthn - writing clean, well-tested backend code in Java, Go, or C#.
  • Contribute to design specs and research spikes for features in your area, alongside more senior engineers who lead the design.
  • Implement identity and federation protocols used by the platform, including Kerberos, LDAP, WebAuthn/FIDO2, and TOTP. Familiarity with SAML/OIDC is useful for interop conversations with adjacent teams.
  • Partner with the Product Owner and tech lead on story-level scope, sequencing, and dependencies for your own work, and help refine and clarify work items before they land in a sprint.

  • Reliably deliver as a developer, reviewer, and tester - high test coverage, clean code, and reviews that catch issues before they land, with a security-first mindset appropriate for tier-0 services.
  • Apply Salesforce engineering best practices to code, tests, and CI/CD pipelines. Leave code in better shape than you found it.
  • Use AI development tools (e.g.Claude Code) in your day-to-day workflow, and critically evaluate both human and AI-generated code for correctness, performance, and security compliance.
  • Analyze and fix bugs in your area, working with more senior engineers on the complex ones. Debug production issues and drive them to a fix.
  • Exhibit ownership beyond just coding your features - an active role in testing, review, and monitoring is part of the job, especially given the tier-0 nature of the platform.

  • Participate in the on-call rotation for the Authentication Platform and handle common alerts confidently. On-call is a real, high-visibility part of this role because of the platform’s tier-0 status.
  • Understand the platform’s telemetry - metrics, logs, traces, SLIs - and extend it for the features you own. The availability target is 4+ nines.
  • Contribute to Root Cause Analyses for incidents in your area, and follow through on assigned action items.

  • Work with internal stakeholders - service teams and infrastructure owners who depend on the Authentication Platform - to answer integration questions about the features you own.
  • Author and maintain technical documentation and runbooks for your work.

Requirements

Strong programming ability in Java, Go, or C#, with production experience building backend services.

  • Working knowledge of at least one identity or federation protocol from this set: Kerberos, LDAP, WebAuthn/FIDO2, TOTP, SAML, OIDC. Deeper experience in one or more is a plus.
  • Experience building, deploying, and debugging distributed services in a Public Cloud environment (AWS or GCP) or a hybrid deployment, using Kubernetes and modern CI/CD.
  • Solid grasp of software fundamentals: data structures, testing, code review, source control, CI/CD, and Agile execution as a team member.
  • A security-first mindset - writing code with least-privilege defaults, threat-aware reviews, and thorough automated testing appropriate for identity-critical systems.
  • Ability to debug production issues in a distributed system using logs, metrics, and traces.
  • Comfortable executing an agreed-upon plan largely independently, escalating design-level and cross-cutting decisions to senior engineers.

Preferred Requirements

  • IAM specialist depth - familiarity with the internals of one or more of Kerberos, LDAP, WebAuthn/FIDO2, TOTP, and the interop story with SAML/OIDC.
  • Security hardening - familiarity with HSMs, PKI, and secure credential storage patterns.
  • Compliance and auditing - exposure to controls and evidence requirements under PCI, SOC 2, or HIPAA.
  • Operational grit - experience on-call for a high-visibility production service, and comfort debugging live incidents under pressure.
  • Experience integrating AI development tools into engineering workflows, including prompt design and reviewing AI-generated code for security-critical systems.

Education -Master’s degree (or foreign equivalent) in Computer Science, Cybersecurity, Software Engineering, or a related field. A Bachelor’s degree (or foreign equivalent) is acceptable with additional years of experience.

Minimum years of experience

  • 3 years of software engineering experience

Benefits & conditions

benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.

The typical base salary range for this position is $117,200 - $176,700 annually.

The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

About the company

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce., Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on salesforce.wd12.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all