
Platform Security Architect
Salesforce · Posted Sep 28
Customer relationship management, cloud computing, enterprise software, and artificial intelligence solutions
Get a personal compatibility score
Add a resume for personal matches
About the role
Salesforce is the #1 AI CRM, and the platform organization is responsible for keeping its own Salesforce ecosystem secure. The Platform Security Architect owns the hands-on design and implementation of security controls within the Salesforce org, covering Sharing and Visibility, Shield encryption, identity and SSO flows, event monitoring, and Connected App/OAuth governance. The role works alongside developers and admins as the security gatekeeper for Apex and LWC deployments through the CI/CD pipeline, translating abstract security policies into concrete Salesforce configurations.
What you will do
- Sharing Architecture: Design and implement complex sharing models. Optimize Org-Wide Defaults (OWD), Sharing Rules, Account Teams, and Territory Management to ensure strict data segregation.
- Shield Implementation: Lead the technical deployment of Salesforce Shield. Manage Tenant Secrets, define encryption policies for standard/custom fields, and configure Field Audit Trails to meet retention policies.
- Identity Configuration: Configure and troubleshoot SSO (SAML/OIDC), Connected Apps, and Login Flows. managing certificates and Key Management (BYOK) where applicable.
- Real-Time Monitoring: Build Transaction Security Policies (using Apex or Low-Code) to block data exfiltration attempts in real-time.
- Log Analysis: Configure Event Monitoring to export logs to our SIEM (Splunk/New Relic). Create dashboards to visualize login anomalies and report exports.
- Code Security: Act as the "Security Gatekeeper" for deployments. Review Apex and LWC code for common vulnerabilities (SOQL Injection, XSS, Enforcing Sharing).
- DevOps Integration: Configure static code analysis tools (e.g., PMD, Checkmarx, Clayton) within our CI/CD pipeline (Copado/Gearset/Jenkins) to auto-reject insecure code.
- OAuth Flow Architecture: Select and implement the correct OAuth flows for specific use cases (e.g., JWT Bearer Flow for server-to-server integration vs. Web Server Flow for user-facing apps vs. Device Flow for IoT).
- Scope Management: Enforce the principle of Least Privilege by meticulously defining and auditing OAuth Scopes (e.g., ensuring an integration only has api access and not full access).
- Session Policies: Configure granular session policies per Connected App, enforcing High Assurance sessions (MFA) for sensitive apps and defining strict timeout values.
- Client Secret Management: Manage the lifecycle of Consumer Keys and Secrets, including rotation strategies and ensuring secrets are never hardcoded in external systems.
- IP Relaxation: configure "Enforce IP Restrictions" vs "Relax IP Restrictions" settings on a per-app basis to balance security with accessibility.
- Security Center & Multi-Org Governance
- Centralized Policy Management: Implement and manage Salesforce Security Center to define and push baseline security policies (e.g., Password Policies, Session Settings, Trusted IP Ranges) from a central tenant to all child orgs.
- Drift Detection: Configure Security Center to monitor for Configuration Drift. Create alerts that trigger immediately if a local admin in a child org attempts to weaken security settings (e.g., disabling MFA or relaxing IP restrictions).
- Health Visibility: Maintain a single-pane-of-glass view of security health scores across the entire multi-org landscape, reporting on KPI improvements to leadership.
- Platform Limits: Advise the business on the performance impacts of security decisions (e.g., "How will encrypting this field impact SOQL query performance?").
- Release Readiness: Review the Salesforce Release Notes (3x/year) specifically for security updates (e.g., MFA enforcement, Browser policy changes) and proactively prepare the org.
Skills used in this role
What the employer is looking for
- 10+ Years of hands-on experience in the Salesforce ecosystem as a Technical Architect, Developer, or Senior Administrator.
- Sharing & Visibility Master: You can explain "Implicit Sharing," "Group Maintenance Tables," and "Apex Managed Sharing" in your sleep.
- Apex & Metadata Fluency: You can read Apex triggers and understand how to query the LoginHistory or SetupAuditTrail objects via SOQL.
- Implementation Experience: Proven track record of actually turning on and configuring Platform Encryption, Event Monitoring, or multi-factor authentication in a large, complex org.
- Understanding of basic security concepts: Least Privilege, Separation of Duties, Encryption (At Rest vs. In Transit), and CIA Triad.
- Familiarity with common web vulnerabilities (OWASP Top 10) specifically in the context of Salesforce (e.g., "How to prevent XSS in Visualforce/LWC").
- Required: Salesforce Certified System Architect (or progress towards it).
- Required: Salesforce Certified Sharing and Visibility Architect.
- Required: Salesforce Certified Identity and Access Management Architect.
Preferred qualifications
- Bonus: Salesforce Certified Technical Architect (CTA).
Benefits and support
- Compensation and benefits are detailed in the job posting
About Salesforce
Salesforce, Inc. is a leading global cloud-based enterprise software company specializing in customer relationship management (CRM) and artificial intelligence solutions. Through its integrated Customer 360 platform, the company provides applications for sales, customer service, marketing automation, e-commerce, and analytics. Powered by innovations like Agentforce, Salesforce helps businesses bridge human capability with autonomous AI agents to drive customer success.
- Industry
- Cloud Computing
- Company size
- 87000+ employees
- Founded
- 1999
- Location
- San Francisco, California, USA
- Funding stage
- Public Company
Funding
Public Company · $25B raised
- 2026-03Post-IPO Debt$25B
- 2003-01Venture Round$1M
- 2001-06Series D$46.9M
- 1999-11Series C$13.2M
- 1999-06Series B$3.8M
Leadership
Chair, Chief Executive Officer & Co-Founder
President & Chief Operating and Financial Officer
Co-Founder & Chief Technology Officer, Slack
President & Chief Strategy Officer
Recent coverage
Dealroom
Salesforce to Acquire Listen Labs to Expand AI Research Capabilities2026-09-29
Stock Titan
Salesforce Highlights Margin Expansion and Growth Targets at 2026 Investor Day2026-09-17
Salesforce News
Live Nation Makes Show Day Easier for Fans With Salesforce's Agentforce2026-09-16
Investing.com
Salesforce Prices Record $25 Billion Senior Notes Offering for Share Repurchase2026-03-12