Salesforce Security Engineer and System Security Officer responsible for security compliance in Federal Government programs. Collaborating with teams to integrate security throughout the DevSecOps pipeline.
Responsibilities
Provide subject matter expertise throughout the system development lifecycle and interface with multiple stakeholders through multiple touchpoints weekly.
Manage coordination and response to agency security-related inquiries, compliance with agency policies, implementation of security controls, and maintenance of security documentation and artifacts.
Lead Security Impact Analyses (SIAs), integrate automated security validation into CI/CD pipelines, and ensure tools are configured and tuned for maximum effectiveness.
Champion the integration of automated security testing into the CI/CD pipeline to align with continuous delivery practices. Integrate security controls into CI/CD pipelines (GitHub Actions, Jenkins, Copado, Terraform, Kubernetes).
Mentor product and engineering teams on secure development practices and continuous security; translate and tailor NIST 800-53 Rev 5 and CMS security controls into actionable tasks for DevSecOps teams.
Requirements
A Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
Deep, practical knowledge of Salesforce security architecture, including Profiles vs Permission Sets, Permission Set Groups, Sharing Rules, Role Hierarchies, Record-Level Security, and Delegated Administration
Minimum of 8 years experience implementing security controls and monitoring compliance for systems, in accordance with federal system security and privacy regulations.
Strong understanding of continuous automated security practices applied to data and application engineering teams.
Hands-on configuration and operation of security tools (Snyk, AppOmni, Tenable, Invicti, Splunk, AWS SecurityHub), including integration into CI/CD pipelines.
Strong technical knowledge of Salesforce security best practices (roles, profiles, permission sets, OAuth/MFA, AppOmni).
Identity Security Specialist developing custom identity management solutions at Lincoln Electric. Leading integration with systems like Active Directory and ensuring compliance with security policies in a global context.
OT Security Consultant at Sword delivering security across operational and industrial environments. Leading assessments and improvement plans while collaborating with engineering and asset teams.
Lead cybersecurity operations for Operational Technology at NTT DATA Romania. Focus on security threat detection, response, and optimization in various customer environments.
Offensive Security Engineer at Replit leading penetration testing and security for cloud - native platform. Focused on securing AI - integrated system through advanced adversarial tactics and code analysis.
Network Security Engineer safeguarding enterprise infrastructure and managing security operations. Leading vulnerability remediation and driving automation within the Engineering Security Operations Team.
Senior Network Security Engineer developing and deploying network security posture for Genworth. Collaborating with teams to manage hardware and software security initiatives in cloud and datacenter environments.
IT Risk & Security Specialist responsible for managing cybersecurity and system risk for Merpay's fintech operations. Collaborating with teams to enhance GRC management across the organization.
Security Management Specialist for Mercari overseeing information security governance and compliance, collaborating with GRC teams within the organization.
AI Security Principal Engineer at MYOB delivering secure AI products while safeguarding against cyber threats. Join a leading business management solution supporting Australian and New Zealand businesses.