Salesforce.com, Inc Software Development Engineer (ALL LEVELS) - Distributed Systems Security in Bellevue, Washington
Job CategoryProducts and Technology
Trust is the #1 company value at Salesforce. Salesforce.com hosts web services and applications written by thousands of internal developers and tens of thousands of customers to provide the largest SaaS platform on the planet.
Our Security Software Engineering team builds and operates highly scalable, fault-tolerant, distributed systems to deliver cloud-scale security software services. We provide the fundamental building blocks to improve and preserve customer trust in Salesforce's products across multiple public cloud substrates and our own network infrastructure. We leverage many open source technologies, including big data, machine learning, no-SQL database, container, Kubernetes, Istio to architect and implement our services, to protect Salesforce products/infrastructure and defend against malicious attacks. Our products' massive complexity requires our software engineers to be highly adoptive to new technology and methodologies and have the strong ability to deliver reliable software services under pressure. Prior security knowledge is not strictly required. You will have the unique opportunity to learn from the best industry security experts and integrate that into your software and service engineering.
Our expanding team is looking for experienced Distributed Systems Developer (position level dependent on experience).
Click to learn more about our Culture and our Engineering organization through these videos!
Some key investments in our space include:
Security Foundation Services:
Develop and deliver reliable and scalable foundational services. These key building blocks - like key and secret management systems, PKI (public key infrastructure), service-to-service authn/authz and data encryption - enable the security of all other services and permit the protection of our customer data.
Identity and Access:
Design and implement consistent and scalable identity and access services for all of Salesforce, integrating our IT network, public cloud infrastructure, and our own data centers, and empowering all our engineers to operate these environments in a secure manner.
Threat Detection and Response Services:
Develop highly scalable, automatic and flexible defense system integrating extensive data collection, big data processing, machine learning detection, automatic response, and automatic mitigation across all our data centers, IT infrastructure and public cloud environments.
Trust is Salesforce’s number one value. And we invest heavily in the security space to create the most secure enterprise cloud platform. Threat Detection & Response is one of the most critical components of our security defense system. It involves complex subsystems including massive data collection, detection through complex rules and machine learning, highly scalable response automation, deep investigation capability, and mitigation solutions. All these solutions are built in our cloud environment with large scale distributed system. The architects in the D&R Engineering organization will partner with engineering managers to guide the team to design, implement and run these complex services. You are expected to bring in deep architecture and design knowledge, excellent engineering practice, as well as capability to provide a high-quality hands-on implementation.
Threat and Vulnerability Management Engineering:
Design, development and implement scalable vulnerability management infrastructure for all of Salesforce, integration of diverse assets data within data centers, public cloud infrastructures, IT network, and provide threat / risk reporting.
Secure Software Development Lifecycle:
Under this umbrella, we design, build and deliver highly available, disaster proof, public cloud hosted services for the entire Salesforce developer community and increase the security of Salesforce's products. Just a few of these include Credentials Scanning as a Service (find secrets and credentials hidden in our source code), Container Scanning as a Service (ensure that the container images being deployed for AWS, GCP, and Gov Cloud are free of vulnerabilities), 3PP as a Service (ensure that we do not inherit a third party developer's security vulnerabilities), Static Code Analysis as a Service (ensure that the Salesforce's own code -in any language- is free of security Vulnerabilities). These projects are all targeted directly at the developer community and have various touch points including integration with various CI and SCM systems.
Continuous Security Monitoring (CSM):
CSM is a continuous process of evidence collection, comparison of evidence to a known standard, and flagging divergence thereby assuring operating effectiveness of security controls. This involves collecting bits of data from endpoints (we've worked with OSQuery and Tanium), pumping that into a data lake (Kafka endpoints with a Hadoop/Hbase over S3 storage), dockerized containers for the backend and job scheduling and finally working that data into Salesforce Objects for dashboards and analytics.
The Network Security Engineering team is building a new internal cloud platform for various network security controls and management. Our mission is to develop highly-available and performant distributed systems to provide security at the network level in our private and public clouds, including micro-segmentation, network policy distribution, access control at host/device level, distributed firewall and DDoS prevention. Our scope is a wide range of compute substrates, including bare metal hosts, VMs, and containers.
If you have some/most of the key skills below, we have an exciting engineering position for you at all levels:
Experience and passion for service ownership, building reliable/self-healing services.
Experience working in a complex team environment. Able to deliver under pressure and dependency constraints.
Java, Go, Python, C/C++
Knowledge working with relational database MySQL, Postgres
Familiar with open source technologies, such as ZooKeeper, MongoDB
Experience with big data and pipeline technologies, such as Hadoop, Kafka
Knowledge or experience with machine learning
Experience building large scale distributed systems, especially in cloud environments
Familiar with public cloud services with AWS and Google Cloud Platform
Good knowledge with operating systems (Linux, Mac, and Windows)
Good knowledge with network technologies, such as TCP/IP, DNS or load balancer
Experience at Scrum or other agile development methodologies, with attention to code quality, delivering secure code
5+ years of development experience
Proficiency in at least one of the following programming languages: Golang, Java, C++, Python, C#
Mastery of OOO concepts and programming
Demonstrated understanding of general Unix/Linux systems (e.g., CentOS, RHEL, Solaris, or similar)
DevOps mindset and strong ownership over owned code (test, monitor, deploy, maintain)
M.Sc/M.Eng in Computer Science/Engineering or B.A/B.Sc. in same disciplines with the equivalent years of experience.
Salesforce, the Customer Success Platform and world's #1 CRM, empowers companies to connect with their customers in a whole new way. The company was founded on three disruptive ideas: a new technology model in cloud computing, a pay-as-you-go business model, and a new integrated corporate philanthropy model. These founding principles have taken our company to great heights, including being named one of Forbes’s “World’s Most Innovative Company” six years in a row and one of Fortune’s “100 Best Companies to Work For” nine years in a row. We are the fastest growing of the top 10 enterprise software companies, and this level of growth equals incredible opportunities to grow a career at Salesforce. Together, with our whole Ohana (Hawaiian for "family") made up of our employees, customers, partners, and communities, we are working to improve the state of the world.
Salesforce.com and Salesforce.org are Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this Web site or directly to managers. Salesforce.com and Salesforce.org do not accept unsolicited headhunter and agency resumes. Salesforce.com and Salesforce.org will not pay fees to any third-party agency or company that does not have a signed agreement with Salesforce.com or Salesforce.org.
Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants with arrest and conviction records.
Founded in 1999, Salesforce is the global leader in Customer Relationship Management (CRM). Companies of every size and industry are using Salesforce to transform their businesses, across sales, service, marketing, commerce, and more by connecting with customers in a whole new way. We harness technologies that can revolutionize companies, careers, and, hopefully, our world.
Salesforce is built on a set of four core values: Trust, Customer Success, Innovation, and Equality. By making technology more accessible, we're helping create a future with greater opportunity and equality for all. This has taken our company to great heights, including being ranked by Fortune as one of the “Most Admired Companies in the World” and one of the “100 Best Companies to Work For” eleven years in a row, and named “Innovator of the Decade” and one of the “World’s Most Innovative Companies” eight years in a row by Forbes.
There are those who choose to work with the best and brightest. And then, there are those who want to do more than just a job. They are the ones improving lives, not only their careers. Having an impact now instead of later. Doing something that’s so much bigger than themselves, an industry, and their company.
We believe everyone can be a Trailblazer. Join Salesforce and discover a future of new opportunities.