Haystack
← Back to Jobs
Technology

Salesforce Platform Security Engineer

Maven CompaniesSeattle, WA🇺🇸United StatesPosted 20 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

We are seeking an experienced Salesforce Platform Security Engineer with 8–12 years of IT experience and deep expertise in Salesforce Security, Identity & Access Management (IAM), Application Security, Governance, Risk, and Compliance. The ideal candidate will design, implement, assess, and govern security controls across the Salesforce ecosystem while ensuring compliance with enterprise security standards and regulatory requirements.

The role requires strong technical knowledge of Salesforce security architecture, secure application development, authentication protocols, platform encryption, monitoring, and security best practices.


Key Responsibilities

Salesforce Platform Security

  • Design and implement Salesforce security architecture aligned with enterprise security standards.

  • Configure and manage Profiles, Permission Sets, Permission Set Groups, Roles, Public Groups, and Queues.

  • Design scalable record access models using:

    • Organization-Wide Defaults (OWD)

    • Role Hierarchy

    • Sharing Rules

    • Manual Sharing

    • Apex Managed Sharing

  • Implement Object-Level, Field-Level, and Record-Level Security.

  • Manage CRUD, View All, Modify All, and delegated administration permissions.

  • Configure Salesforce Shield Platform Encryption and evaluate encryption strategies.

  • Perform regular security reviews and recommend least-privilege access models.


Identity & Access Management (IAM)

  • Design and implement Single Sign-On (SSO) solutions using SAML and OAuth.

  • Configure Identity Providers (IdP) and Service Providers (SP).

  • Implement Multi-Factor Authentication (MFA) across Salesforce environments.

  • Configure Connected Apps with secure authentication policies.

  • Manage:

    • IP Restrictions

    • Session Policies

    • Refresh Token Policies

    • OAuth Scopes

  • Design secure API authentication mechanisms.

  • Configure Login Flows and Login IP restrictions.

  • Implement Identity Federation and secure external integrations.


Application Security

  • Perform secure code reviews for Apex, Lightning Web Components (LWC), Aura Components, and Visualforce.

  • Identify and remediate:

    • SOQL Injection

    • SOSL Injection

    • Cross-Site Scripting (XSS)

    • Cross-Site Request Forgery (CSRF)

    • Insecure Data Access

  • Apply secure coding standards using:

    • with sharing

    • without sharing

    • inherited sharing

  • Implement Named Credentials and External Credentials.

  • Review Apex classes for CRUD/FLS enforcement.

  • Ensure secure API integrations and authentication mechanisms.


Monitoring & Compliance

  • Configure and monitor:

    • Salesforce Shield

    • Event Monitoring

    • Health Check

    • Security Center

    • Login History

    • Setup Audit Trail

    • Transaction Security Policies

  • Perform security audits and vulnerability assessments.

  • Support compliance initiatives including:

    • GDPR

    • HIPAA

    • SOC 2

    • ISO 27001

  • Develop security baselines and governance standards.

  • Investigate security incidents and perform root cause analysis.


Governance & Risk Management

  • Define Salesforce security policies and standards.

  • Conduct periodic access reviews and permission audits.

  • Manage segregation of duties (SoD).

  • Support risk assessments and remediation planning.

  • Ensure compliance with organizational security frameworks.

  • Collaborate with Security, Infrastructure, IAM, and Development teams.


Incident Response

  • Investigate unauthorized access attempts.

  • Analyze Event Monitoring logs.

  • Respond to suspected data breaches.

  • Coordinate containment, remediation, and recovery activities.

  • Prepare incident reports and security recommendations.


Required Technical Skills

Salesforce Security

Identity & Authentication

Application Security

Salesforce Shield

Monitoring & Governance

 


Required Experience

  • 8–12 years of overall IT experience.

  • 5+ years of hands-on Salesforce Security implementation experience.

  • Experience securing enterprise Salesforce environments.

  • Experience implementing SSO, MFA, OAuth, and SAML integrations.

  • Strong understanding of Salesforce security architecture.

  • Experience with Salesforce Shield implementation.

  • Experience conducting security assessments and audits.

  • Experience supporting regulated environments.

 


 

Skills

Encryption
MFA
OAuth
SAML
SOC 2
SSO
GDPR
HIPAA

Similar jobs