Salesforce logo

Platform Security Architect

Salesforce · Posted Sep 28

Customer relationship management, cloud computing, enterprise software, and artificial intelligence solutions

Indiana - IndianapolisFull-timeOnsiteSenior Level10+ years$150K–$210K yearly100+ applicants
Cloud ComputingEnterprise SoftwareCustomer Relationship ManagementArtificial IntelligenceSaaSPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

Salesforce is the #1 AI CRM, and the platform organization is responsible for keeping its own Salesforce ecosystem secure. The Platform Security Architect owns the hands-on design and implementation of security controls within the Salesforce org, covering Sharing and Visibility, Shield encryption, identity and SSO flows, event monitoring, and Connected App/OAuth governance. The role works alongside developers and admins as the security gatekeeper for Apex and LWC deployments through the CI/CD pipeline, translating abstract security policies into concrete Salesforce configurations.

What you will do

  • Sharing Architecture: Design and implement complex sharing models. Optimize Org-Wide Defaults (OWD), Sharing Rules, Account Teams, and Territory Management to ensure strict data segregation.
  • Shield Implementation: Lead the technical deployment of Salesforce Shield. Manage Tenant Secrets, define encryption policies for standard/custom fields, and configure Field Audit Trails to meet retention policies.
  • Identity Configuration: Configure and troubleshoot SSO (SAML/OIDC), Connected Apps, and Login Flows. managing certificates and Key Management (BYOK) where applicable.
  • Real-Time Monitoring: Build Transaction Security Policies (using Apex or Low-Code) to block data exfiltration attempts in real-time.
  • Log Analysis: Configure Event Monitoring to export logs to our SIEM (Splunk/New Relic). Create dashboards to visualize login anomalies and report exports.
  • Code Security: Act as the "Security Gatekeeper" for deployments. Review Apex and LWC code for common vulnerabilities (SOQL Injection, XSS, Enforcing Sharing).
  • DevOps Integration: Configure static code analysis tools (e.g., PMD, Checkmarx, Clayton) within our CI/CD pipeline (Copado/Gearset/Jenkins) to auto-reject insecure code.
  • OAuth Flow Architecture: Select and implement the correct OAuth flows for specific use cases (e.g., JWT Bearer Flow for server-to-server integration vs. Web Server Flow for user-facing apps vs. Device Flow for IoT).
  • Scope Management: Enforce the principle of Least Privilege by meticulously defining and auditing OAuth Scopes (e.g., ensuring an integration only has api access and not full access).
  • Session Policies: Configure granular session policies per Connected App, enforcing High Assurance sessions (MFA) for sensitive apps and defining strict timeout values.
  • Client Secret Management: Manage the lifecycle of Consumer Keys and Secrets, including rotation strategies and ensuring secrets are never hardcoded in external systems.
  • IP Relaxation: configure "Enforce IP Restrictions" vs "Relax IP Restrictions" settings on a per-app basis to balance security with accessibility.
  • Security Center & Multi-Org Governance
  • Centralized Policy Management: Implement and manage Salesforce Security Center to define and push baseline security policies (e.g., Password Policies, Session Settings, Trusted IP Ranges) from a central tenant to all child orgs.
  • Drift Detection: Configure Security Center to monitor for Configuration Drift. Create alerts that trigger immediately if a local admin in a child org attempts to weaken security settings (e.g., disabling MFA or relaxing IP restrictions).
  • Health Visibility: Maintain a single-pane-of-glass view of security health scores across the entire multi-org landscape, reporting on KPI improvements to leadership.
  • Platform Limits: Advise the business on the performance impacts of security decisions (e.g., "How will encrypting this field impact SOQL query performance?").
  • Release Readiness: Review the Salesforce Release Notes (3x/year) specifically for security updates (e.g., MFA enforcement, Browser policy changes) and proactively prepare the org.

Skills used in this role

SalesforceApexSOQLLWCVisualforceSalesforce ShieldPlatform EncryptionEvent MonitoringSAMLOIDCOAuthJWTSSOMFASplunkNew RelicPMDCheckmarxClaytonCopadoGearsetJenkinsCI/CDBYOKSecurity Center

What the employer is looking for

  • 10+ Years of hands-on experience in the Salesforce ecosystem as a Technical Architect, Developer, or Senior Administrator.
  • Sharing & Visibility Master: You can explain "Implicit Sharing," "Group Maintenance Tables," and "Apex Managed Sharing" in your sleep.
  • Apex & Metadata Fluency: You can read Apex triggers and understand how to query the LoginHistory or SetupAuditTrail objects via SOQL.
  • Implementation Experience: Proven track record of actually turning on and configuring Platform Encryption, Event Monitoring, or multi-factor authentication in a large, complex org.
  • Understanding of basic security concepts: Least Privilege, Separation of Duties, Encryption (At Rest vs. In Transit), and CIA Triad.
  • Familiarity with common web vulnerabilities (OWASP Top 10) specifically in the context of Salesforce (e.g., "How to prevent XSS in Visualforce/LWC").
  • Required: Salesforce Certified System Architect (or progress towards it).
  • Required: Salesforce Certified Sharing and Visibility Architect.
  • Required: Salesforce Certified Identity and Access Management Architect.

Preferred qualifications

  • Bonus: Salesforce Certified Technical Architect (CTA).

Benefits and support

  • Compensation and benefits are detailed in the job posting

About Salesforce

Salesforce, Inc. is a leading global cloud-based enterprise software company specializing in customer relationship management (CRM) and artificial intelligence solutions. Through its integrated Customer 360 platform, the company provides applications for sales, customer service, marketing automation, e-commerce, and analytics. Powered by innovations like Agentforce, Salesforce helps businesses bridge human capability with autonomous AI agents to drive customer success.

Industry
Cloud Computing
Company size
87000+ employees
Founded
1999
Location
San Francisco, California, USA
Funding stage
Public Company

Funding

Public Company · $25B raised

Emergence CapitalMeritech Capital PartnersSunBridgeStarboard ValueWilliam Hambrecht
  • 2026-03Post-IPO Debt$25B
  • 2003-01Venture Round$1M
  • 2001-06Series D$46.9M
  • 1999-11Series C$13.2M
  • 1999-06Series B$3.8M

Leadership

MB
Marc Benioff

Chair, Chief Executive Officer & Co-Founder

RW
Robin Washington

President & Chief Operating and Financial Officer

PH
Parker Harris

Co-Founder & Chief Technology Officer, Slack

DS
David Schmaier

President & Chief Strategy Officer