Software Engineering SMTS, Enterprise IAM

Airkit
Airkit

Software Engineering

Bellevue, WA, USA

Posted on Jul 28, 2026

Description

The Experience

The Enterprise Security Engineering team builds and operates highly scalable, fault-tolerant, distributed systems that deliver cloud-scale Identity and Access Management (IAM) services across Salesforce's enterprise network, public cloud infrastructure, and internal data centers. We provide the core building blocks for identity lifecycle, governance, authentication, authorization, and privileged access management that protect customer trust and empower every Salesforce engineer to operate securely, regardless of environment.
As a full-stack software engineer on this team, you will design and build end-to-end IAM capabilities — from backend services and APIs to the user-facing experiences that power access requests, provisioning, entitlement management, and access certifications at enterprise scale. You will help secure the emerging agentic enterprise by designing controls for AI agents and autonomous workloads, and you will play a foundational role in advancing Salesforce's Zero Trust architecture.

What You'll Actually Be Doing

  • Design, build, and operate scalable IAM services and APIs spanning identity lifecycle, access requests, entitlement and role management, and access certifications.

  • Build Privileged Access Management (PAM) capabilities — credential vaulting and rotation, session control, secrets management, and just-in-time (JIT) access flows that grant elevated, time-bound entitlements and revoke them automatically.

  • Model and secure non-human identities (NHI) — service accounts, agents, workloads, and machine credentials — including issuance, rotation, and lifecycle governance.

  • Develop full-stack features, backend services, and modern web front-ends that deliver intuitive self-service and administrative experiences for IAM.

  • Build and manage containerized workloads with Kubernetes, Docker, and infrastructure-as-code (IaC) tools such as Terraform; operate services in a full DevOps model (monitor, troubleshoot, continuously improve).

  • Integrate across identity sources, directories, and downstream applications using System for Cross-domain Identity Management (SCIM), REST, and event-driven patterns.

  • Partner with governance and compliance teams to embed Separation of Duties (SoD), least-privilege, and audit controls (Sarbanes-Oxley (SOX), National Institute of Standards and Technology (NIST), SOC 2) into the platform.

  • Write clean, maintainable, secure code; participate in design and code reviews; and champion secure Software Development Life Cycle (SDLC) practices.

  • Collaborate with cross-functional teams across security, infrastructure, product, and engineering to ensure platform integrity and trustworthiness.

  • Create and maintain technical documentation, runbooks, and enablement materials.

  • Design significant features, mentor junior engineers, and drive technical direction and continuous improvement across the platform.

  • Build and ship high-quality, production-grade software using modern engineering practices, with AI as a core part of your development workflow — pushing the boundaries of AI development tools to deliver secure, optimized, and high-quality code.

  • Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation at scale.

  • Contribute to building and maintaining shared system context — an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably. Critically evaluate code (human- or AI-generated) for correctness, quality, security, and performance.

You're Our Person If...

  • You have 5 or more years of professional software development experience building distributed systems in Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS) environments.

  • You have full-stack development proficiency: strong backend skills in Java, Go, and/or Python, plus front-end experience with modern frameworks such as React.

  • You have a solid understanding of the IAM domain, identity governance and lifecycle, authentication, authorization, Role-Based Access Control (RBAC) and entitlement models, privileged access management including just-in-time access, and common protocols (OAuth 2.0, OpenID Connect (OIDC), Security Assertion Markup Language (SAML), SCIM, Lightweight Directory Access Protocol (LDAP)).

  • You have experience designing and consuming REST Application Programming Interfaces (APIs) (JSON/XML, OpenAPI/Swagger) and integrating heterogeneous systems.

  • You have strong experience on public cloud platforms (AWS, Azure, or GCP), including containers (Docker, Kubernetes), and infrastructure-as-code tools such as Terraform.

  • You have hands-on experience with Continuous Integration and Continuous Delivery (CI/CD) and source control (Git, Jenkins, or equivalent), including secure coding and defensive programming.

  • You have a solid grasp of DevOps practices, monitoring, and ownership of production systems in high-availability environments.

  • You bring strong problem-solving, debugging, communication, and collaboration skills.

  • You bring a demonstrated, genuine AI-first approach to engineering — using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty.

  • You have experience using AI tools (such as Claude Code, GitHub Copilot, Codex, or Cursor) in development workflows.

  • You have advanced prompt engineering skills and the ability to write precise, structured prompts and cultivate the system context that makes AI outputs reliable, secure, and production-ready.

  • You hold a Bachelor's degree in Computer Science, Engineering, or a related field, or have equivalent practical experience.

Even Better If...

  • You have experience integrating AI and agentic capabilities into IAM workflows or user experiences.

  • You have experience working with globally distributed teams and large enterprises.

  • You have familiarity with commercial IAM platforms such as SailPoint, Okta, CyberArk, or Active Directory/Entra ID — as a consumer or integrator (this is not required as a specialty).

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.