Salesforce Security Engineer
Job Description
Join AWS as a Salesforce Security Engineer in Dallas, onsite. This role offers a competitive annual salary range of USD 159,300 to 202,400, along with a comprehensive benefits package that includes medical, dental, vision, and prescription coverage, Basic Life and AD and D insurance with an option for supplemental life plans, employee assistance program, mental health resources, flexible spending accounts, and Adoption and Surrogacy reimbursement. Additional benefits include 401(k) matching, paid time off, parental leave, sign-on payments, and restricted stock units. The role centers on building automated security scanning, detections, and guidance to secure Salesforce deployments across AWS.
Responsibilities
- Build and maintain automated security scanning and evaluation capabilities that assess Salesforce org configurations against defined security standards
- Apply deep Salesforce platform knowledge to identify security risks in profiles, permission sets, sharing rules, connected apps, session settings, and custom Apex code
- Develop detections for configuration changes that introduce security risk, and deliver escalation workflows that route findings to the right owners
- Partner with service owners to interpret security findings, prioritize remediation, and implement secure configurations within their Salesforce environments
- Write and refine security evaluations that measure operational maturity across the Salesforce fleet
- Develop customer-facing guidance, documentation, and training that help service owners understand and resolve Salesforce security findings independently
- Collaborate with Amazon enterprise security teams to translate security requirements into Salesforce-specific implementation patterns
- Stay current with Salesforce platform releases, AI innovations, and security features, assessing their impact on Amazon's security posture and updating tooling accordingly
- Support other teams performing security reviews, vulnerability analysis, and incident response when Salesforce expertise is required
Requirements
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Experience using Salesforce
Technologies
- Salesforce, SOQL, Apex, Salesforce platform APIs, OAuth, SAML, SSO, Connected apps, Named credentials, AWS infrastructure
Preferred Qualifications
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
- Experience with AWS products and services
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
- 4+ years of hands-on experience with the Salesforce platform, including administration, security configuration, and development
- Proficiency in SOQL for data extraction and security detection, with working knowledge of Salesforce metadata schema and platform APIs