Salesforce Security Engineer
Job Description
Steampunk is hiring a Salesforce Security Engineer (onsite in McLean, VA) to strengthen security across the Salesforce environment, support ISSO and ATO activities, and use Splunk for monitoring and incident investigation.
Responsibilities
- Design, implement, and audit Salesforce access controls, including profiles, permission sets, roles, sharing rules, and field-level security, using least privilege across all user populations
- Run periodic access reviews and recertifications to find and remediate overly permissive or outdated access
- Configure and maintain Salesforce security settings in the Setup Menu, including session security, login IP ranges and restrictions, password policies, MFA enforcement, Health Check, Shield Platform Encryption, and Event Monitoring
- Build and maintain Splunk queries and dashboards for Salesforce login events, permission changes, and anomalous access patterns
- Support incident investigations by analyzing logs from relevant Salesforce security telemetry
- Assess and harden web application security for Salesforce Connected Apps, including internet-facing controls such as CORS, CSP, Trusted URLs, OAuth/Connected App policies, and session security
- Help ISSOs secure their applications and gather security artifacts for assessment and authorization activities
- Coordinate with system owners and compliance teams to keep security configurations aligned with federal requirements (for example, NIST 800-53 and FedRAMP as applicable)
- Document security configurations, findings, and remediation steps to support audit and ATO efforts
- Review and provision privileged user access
Requirements
- Ability to obtain and maintain a U.S. Government security clearance
- Bachelor’s degree
- 8–10 years of experience in Salesforce administration or security engineering
- Strong knowledge of Salesforce access control models (profiles, permission sets, roles, sharing rules) and least privilege implementation
- Extensive experience configuring Salesforce Setup Menu security controls, including session security, login policies, Health Check, Event Monitoring, and Shield Platform Encryption
- Proficiency writing Splunk SPL for log analysis, monitoring, and alerting
- Working knowledge of web application security concepts covering CSP, CORS, trusted domains, and OAuth flows
Technologies
- Salesforce
- Splunk, SPL
- Shield Platform Encryption
- Multi-factor authentication (MFA)
- Health Check
- Event Monitoring
- CORS
- Content Security Policy (CSP)
- OAuth
- Connected Apps
Preferred
- Salesforce Administrator (ADM 201) or a Salesforce security-related certification
- One of the following security certifications: CISSP, CISM, or similar
- Familiarity with NIST 800-53 security controls
- Experience supporting federal government clients or ATO processes