Software Engineering PMTS

Salesforce

San Francisco (CA)

On-site

USD 197,000 - 314,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Salesforce is seeking a seasoned security software engineer to own the design and hands-on implementation for defending our production database platform. You will build detection, enforcement, and anomaly-detection capabilities at scale, partnering with database engineering to embed security into the platform from design to production rollout.

The role requires 10+ years in security for distributed databases, expert-level knowledge of multi-tenant isolation, and strong coding skills in Python,

Qualifications

  • 10+ years of professional security experience with distributed databases or multi-tenant SaaS architectures.
  • Experience leading threat modeling and architecture risk analysis for complex distributed database cloud environments.
  • Expert-level design of consistent security policies across AWS and GCP, including mitigating provider-specific edge cases.
  • Strong programming skills in Python / Rust / Go.
  • Hands-on experience building or improving security detection and enforcement software for large-scale production database systems.

Responsibilities

  • Designing security detection and enforcement software for large-scale production database systems
  • Building static and dynamic analysis pipelines for database vulnerability classes: SQL injection, privilege escalation, broken access control, and tenant-isolation breaches
  • Applying ML to anomaly detection: data exfiltration, insider threat, and unusual access to customer data
  • Building security guardrails for AI agents and LLMs operating on production databases: least-privilege configuration, scoped API access, sandbox isolation, and runtime behavioral monitoring
  • Shipping automation for real-time detection and response to fast, automated attacks
  • Driving vulnerability management and software composition analysis across the database platform
  • Partnering with database engineering teams to embed security into the platform, from design review through production rollout

Skills

Python
Rust
Go
Threat modeling
Database security

Tools

AWS
GCP

Job description

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Software Engineering

Job Details
About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Team

Our team owns the defensive security of Salesforce Database — the production database system behind Salesforce's cloud platform, including its storage layer, backup and restore systems, and telemetry and operational infrastructure — storing customer data at a scale and criticality that few systems in the world match. AI has changed the threat landscape: agents opened new production entry points, automated adversarial attacks demand instant response, and vulnerabilities must be addressed in hours. We are building the next-generation defense system for that reality: detection, compliance enforcement, agent security guardrails, and vulnerability management — it runs continuously and acts without waiting on manual review. This role is core to that effort.

What You’ll Do

You will own the design and hands‑on implementation of security software that keeps SDB secure and compliant. Your work will span:

  • Designing security detection and enforcement software for large-scale production database systems
  • Building static and dynamic analysis pipelines for database vulnerability classes: SQL injection, privilege escalation, broken access control, and tenant‑isolation breaches
  • Applying ML to anomaly detection: data exfiltration, insider threat, and unusual access to customer data
  • Building security guardrails for AI agents and LLMs operating on production databases: least‑privilege configuration, scoped API access, sandbox isolation, and runtime behavioral monitoring
  • Shipping automation for real‑time detection and response to fast, automated attacks
  • Driving vulnerability management and software composition analysis across the database platform
  • Partnering with database engineering teams to embed security into the platform, from design review through production rollout
What We’re Looking For
  • Deep understanding of database security, including multi-tenant isolation, access control, and data governance
  • Experience leading threat modeling and architecture risk analysis for complex distributed database cloud environments
  • Expert‑level design of consistent security policies across AWS and GCP, including mitigating provider‑specific edge cases
  • Solid grasp of distributed systems and strong programming skills (Python / Rust / Go)
  • Hands‑on experience building or improving security detection and enforcement software for large-scale production database systems
  • A track record of shipping and operating production software at scale, with a preference for direct delivery over writing specifications
  • Strong written and verbal communication skills; able to lead security discussions across engineering teams and gain buy‑in without formal authority

This role requires 10+ years of professional experience. Experience with large-scale distributed databases or multi‑tenant SaaS architectures is a strong plus.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non‑discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job‑related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com. Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $197,300 - $313,700 annually. In select cities within the San Francisco and New York City metropolitan area, the base salary range for this role is $237,700 - $344,700 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineering SMTS
Software Engineering SMTS

salesforce.com, inc. • Bellevue (WA)

On-site
USD 148,500 - 223,900
Medical, dental, vision insurance
Paid parental leave
401(k) plan
+1
Product Security Senior
Product Security Senior

Salesforce • Bellevue (WA)

On-site
USD 180,000 - 240,000
Product Security Senior
Product Security Senior

salesforce.com, inc. • Bellevue (WA)

On-site
USD 149,000 - 246,000
Product Security Senior
Product Security Senior

Salesforce • San Francisco (CA)

On-site
USD 149,000 - 224,000
Product Security Senior
Product Security Senior

salesforce.com, inc. • San Francisco (CA)

On-site
USD 149,000 - 224,000
Software Engineering MTS
Software Engineering MTS

Salesforce • San Francisco (CA)

On-site
USD 117,000 - 177,000
Product Security Lead
Product Security Lead

Socket.dev • California (MO), Bellevue (WA)

On-site
USD 173,000 - 260,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Senior Platform Software Engineer
Senior Platform Software Engineer

Salesforce • San Francisco (CA)

On-site
USD 149,000 - 246,000
Product Security Lead
Product Security Lead

salesforce.com, inc. • San Francisco (CA)

On-site
USD 173,000 - 260,000