Product Security Engineer, Infrastructure Security

Salesforce Salesforce · Enterprise · Bellevue, WA

Salesforce is seeking a Product Security Engineer for their Infrastructure Security Team. The role involves engineering automated guardrails, contributing to "paved path" templates, and maintaining multi-cloud hygiene. Responsibilities include developing policy-as-code controls, certifying Infrastructure-as-Code modules, maintaining KRI dashboards, and automating manual security processes. The role emphasizes a proactive, scalable approach to security and requires familiarity with Terraform, AWS/GCP security, OPA/Checkov, Python/Go, and integrating security tooling into CI/CD pipelines. A genuine AI-first approach and experience using AI tools with advanced prompt engineering skills are also required.

What you'd actually do

  1. Assist in the engineering and deployment of automated policy-as-code controls (e.g., OPA, Checkov) within CI/CD and runtime environments.
  2. Support the development and certification of Infrastructure-as-Code (IaC) modules. Ensure Terraform and multi-substrate templates adhere to strict security standards before they reach the engineering lifecycle.
  3. Participate in the maintenance of Key Risk Indicator (KRI) dashboards for AWS and GCP. Analyze multi-cloud asset data to identify and remediate privilege escalation paths.
  4. Actively identify manual security processes and develop automated scripts or tooling to eliminate them.
  5. Contribute to building and maintaining the shared system context, an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably.

Skills

Required

  • 2+ years of professional related experience
  • Deep familiarity with Terraform
  • Functional knowledge of AWS or GCP security configurations
  • Experience or strong aptitude for learning OPA (Open Policy Agent) or Checkov
  • Proficiency in Python or Go
  • Understanding of how to integrate security tooling into automated deployment pipelines
  • A demonstrated, genuine AI-first approach to tasks
  • Using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty
  • Experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor, etc.)
  • Advanced prompt engineering skills
  • Ability to write precise, structured prompts
  • Cultivate the system context that makes AI outputs reliable, secure, and production-ready
  • A related technical degree

What the JD emphasized

  • Do not wait for vulnerabilities to hit production.
  • Proactively identify and block insecure configurations at the development stage.
  • Solutions must minimize false positives.
  • High-noise implementations will be rejected.
  • Do not solve for the single instance.
  • Build for the organization.
  • All solutions must scale across all Salesforce Clouds.