Salesforce
Software Engineering PMTS - Cloud Security - Hyderabad
India - Hyderabad · full-time
Company's own boardBachelor's degree
First seen Sep 19 · seen live today · from Salesforce's own Workday board
Skills mentioned
pythonjavagoawsgcpkubernetesterraformci/cdlinuxsalesforce
The posting, as published
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Software Engineering
Job Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
Come join our growing Hyperforce Enterprise Security organization. We are chartered with architecting, implementing, and operating security solutions that protect Salesforce’s complex, multi-cloud technology landscape at scale.
As a Principal Member of Technical Staff, you will provide technical leadership in building the next generation of infrastructure security and developer security guardrails. You will work across the software development and deployment lifecycle to identify security risks early, build scalable controls, and enable secure-by-default engineering practices without compromising developer velocity.
Our team operates at the intersection of cloud security, application security, infrastructure security, DevSecOps, Kubernetes, CI/CD, and runtime security. We build and operate security guardrails that identify and prevent high-risk security issues from source code and Infrastructure as Code through CI/CD and into runtime environments.
You will be expected to operate at both strategic and hands-on technical levels, defining architecture and technical direction while also diving deeply into complex engineering problems, writing production-quality code, and driving solutions from concept through deployment and operation.
This role is an opportunity to shape security capabilities that operate at significant scale across Salesforce infrastructure and to influence how security is embedded throughout the engineering lifecycle.
Responsibilities
Act as a technical leader and subject matter expert for infrastructure security and security guardrails, providing architectural direction across teams.
Design and build scalable shift-left security capabilities that identify security risks in source code, Infrastructure as Code, containerized workloads, and deployment configurations before they reach production.
Architect and build shift-left security controls that identify security risks early while providing developers with actionable findings and straightforward remediation paths.
Design scalable policy-as-code and security enforcement frameworks for consistent security controls across multiple gates and environments.
Drive risk-based security engineering by identifying exploitable, high-impact, and meaningful security risks rather than treating all scanner findings equally.
Design mechanisms for security finding correlation, prioritization, deduplication, and enforcement when signals originate from multiple security systems.
Lead architecture and implementation of Kubernetes admission control and workload security capabilities.
Define technical strategies for reliability, scalability, performance, observability, fault tolerance, and operational readiness of security services.
Establish and evolve SLIs, SLOs, telemetry, rollout strategies, and operational practices for critical security services.
Own technical outcomes across the complete lifecycle — requirements, architecture, implementation, testing, deployment, production readiness, rollout, and ongoing operations.
Continuously identify opportunities to improve security coverage, automation, detection quality, enforcement, and developer experience.
Establish engineering standards and best practices for reliability, scalability, observability, testing, and operational readiness of security services.
Mentor senior engineers and raise the technical bar across the organization.
Influence technical strategy and roadmap decisions across teams and drive initiatives from concept through production.
Build and ship high-quality, production-grade software using modern engineering practices, with AI as a core part of your development workflow by pushing the boundaries of AI development tools to deliver secure, optimized, and high-quality code.
Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation at scale.
Contribute to building and maintaining the shared system context, an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably.
Critically evaluate code (human or AI-generated) for correctness, quality, security, and performance.
Basic Qualifications
Bachelor's degree in Computer Science, a related technical field involving software/systems engineering, or equivalent practical experience.
15+ years of software engineering, systems engineering, security engineering with significant experience designing and delivering large-scale production systems.
Strong programming experience in one or more languages such as Go, Java, or Python, with the ability to design, implement, debug, and review production-quality systems.
Deep understanding of cloud infrastructure and cloud security, including experience with AWS, GCP, or Azure.
Strong hands-on experience with Kubernetes, containers, and cloud-native infrastructure.
Strong understanding of CI/CD architecture and DevSecOps, including deployment pipelines, security gates, policy enforcement, and automation.
Proven experience with Infrastructure as Code, such as Terraform, Helm, CloudFormation, or equivalent technologies.
Experience designing distributed, highly scalable, reliable, and secure systems.
Strong understanding of security engineering concepts including vulnerability management, configuration security, policy enforcement, workload security, identity/access controls, and risk assessment.
Demonstrated ability to take ambiguous security problems, identify the core technical challenge, and drive an architecture and implementation to completion.
Strong written and verbal communication skills, including the ability to explain complex architectures and trade-offs to senior technical and business audiences.
Preferred Qualifications
Deep experience in cloud-native security, DevSecOps, infrastructure security, or application security.
Experience building security platforms/services or guardrails that operate at large enterprise scale.
Experience with Kubernetes Admission Controllers, admission policies, OPA/Gatekeeper, Kyverno, or similar policy enforcement technologies.
Experience with policy-as-code and security-as-code frameworks.
Experience with IaC security and tools such as Checkov, OPA, Terraform security scanning, or equivalent technologies.
Strong understanding of container and workload security, including Seccomp, Linux security mechanisms, container isolation, and runtime security.
Experience building systems that correlate security signals from multiple sources and prioritize findings based on risk, exploitability, exposure, and business impact.
Experience with vulnerability management, cloud security posture management, container security, or automated security remediation.
Experience designing developer-facing security products with a strong focus on actionable findings, low friction remediation, and developer experience.
Experience designing security controls across the complete lifecycle: source → IaC → CI/CD → deployment → admission → runtime.
Strong understanding of cloud networking, identity, workload architecture, and distributed systems.
Experi