About The Position

The Enterprise Security Technology team builds and operates highly scalable, fault-tolerant, distributed systems that deliver cloud-scale security software across multiple public cloud platforms and Salesforce's internal infrastructure. Our key investments are in Identity and Access Management and Public Key Infrastructure (PKI), where we design consistent and scalable services for Salesforce Enterprise, integrating our IT network, public cloud infrastructure, and our own data centers. As a Principal Software Engineer on this team, you help shape the architecture of our nextGen PKI platform, using AI as a core part of your engineering workflow to move faster and deliver secure, production-grade infrastructure at scale.

Requirements

  • 10+ years of experience in enterprise-scale PKI design and operations, with hands-on expertise in EJBCA or comparable CA/RA platforms (e.g., Active Directory Certificate Services (ADCS), Dogtag, Vault PKI)
  • Deep understanding of X.509 certificates, asymmetric cryptography, certificate templates, trust chains, CRLs, and OCSP
  • Proven experience designing and building certificate lifecycle automation and management workflows
  • Hands-on experience with modern enrollment protocols including ACME, EST, CMP, and REST certificate APIs, along with experience migrating workloads from legacy protocols (Network Device Enrollment Service (NDES)/Simple Certificate Enrollment Protocol (SCEP) on ADCS) to modern alternatives
  • Demonstrated ability to lead cross-functional teams in the deployment and modernization of secure identity services
  • Experience with cloud-native PKI in Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP)
  • Familiarity with Hardware Security Module (HSM) integration, key escrow, and secure enclaves
  • Proficiency in programming languages such as Golang and Python
  • Solid understanding of DevOps practices, CI/CD, monitoring, and ownership of production systems
  • Familiarity with source code management and version control systems (Git, Perforce)
  • Proficiency with Linux environments and version control systems (e.g., Git)
  • Demonstrated, genuine AI-first approach to engineering, using AI to move faster, build fluency across the stack, and contribute well beyond your core specialty
  • Experience using AI tools (e.g., Claude Code, GitHub Copilot, Codex, Cursor, etc.) in development workflows
  • Advanced prompt engineering skills and the ability to write precise, structured prompts and cultivate the system context that makes AI outputs reliable, secure, and production-ready
  • Bachelor's or Master's degree in Computer Science, Engineering, Cybersecurity, or a related field, or equivalent experience

Nice To Haves

  • Experience with PKI in Kubernetes or service mesh environments (e.g., Istio, SPIRE, cert-manager)
  • Exposure to IoT device identity, device attestation, or platform security (Trusted Platform Module (TPM), Secure Boot)
  • Awareness of Post-Quantum Cryptography standards and migration considerations (National Institute of Standards and Technology (NIST) PQC)
  • Familiarity with relevant security frameworks and compliance standards (e.g., NIST, International Organization for Standardization (ISO), SOC 2, Federal Information Processing Standards (FIPS) 140-2/3)
  • Experience evaluating and onboarding net-new use cases that require protocol support beyond what legacy ADCS-based infrastructure can provide (e.g., short-lived certificates, ACME-based automation, workload identity, IoT device enrollment)
  • Experience with Certificate Lifecycle Management (CLM) platforms (e.g., Venafi, AppViewX) and certificate observability
  • Broad understanding of core security concepts including Zero Trust, Multi-Factor Authentication (MFA), and secrets management
  • Awareness of common security weaknesses (OWASP Top 10, Common Weakness Enumeration (CWE) Top 25)

Responsibilities

  • Architect and lead the implementation and evolution of Enterprise Java Beans Certificate Authority (EJBCA)-based PKI infrastructure, including Certificate Authority (CA) hierarchies, Enterprise Registration Authority (RA) capabilities, Online Certificate Status Protocol (OCSP) responders, and Certificate Revocation List (CRL) distribution
  • Own the technical design and delivery of the nextGen PKI platform, ensuring scalability, resiliency, security, and compliance across a hybrid cloud environment
  • Lead the adoption and support of modern certificate enrollment and management protocols not supported by legacy CA platforms, including Automated Certificate Management Environment (ACME), Enrollment over Secure Transport (EST), Certificate Management Protocol (CMP), and REST-based certificate Application Programming Interfaces (APIs), enabling automated, scalable certificate management for cloud-native, Internet of Things (IoT), and DevOps workloads
  • Design and build automation frameworks and APIs for certificate provisioning, renewal, revocation, monitoring, and audit logging
  • Drive certificate lifecycle management for internal clients, applications, devices, and workloads at enterprise scale
  • Lead the expansion of PKI into new use cases including IoT device identity, workload identity, mutual Transport Layer Security (mTLS), and Post-Quantum Cryptography (PQC) readiness
  • Integrate certificate-based authentication and automated certificate management across enterprise platforms, Continuous Integration/Continuous Delivery (CI/CD) pipelines, and cloud infrastructure
  • Collaborate with security architects, infrastructure, and application teams to align PKI solutions with organizational policies, regulatory requirements, and compliance standards
  • Provide technical leadership and mentorship to engineers on cryptographic protocols, secure coding practices, and identity primitives
  • Drive incident response and root cause analysis for PKI-related outages or certificate trust failures
  • Develop and maintain architecture documentation, operational runbooks, and PKI standards
  • Build and ship high-quality, production-grade software using modern engineering practices, with AI as a core part of your development workflow, pushing the boundaries of AI development tools to deliver secure, optimized, and high-quality code
  • Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation at scale
  • Contribute to building and maintaining shared system context, an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably, and critically evaluate code (human- or AI-generated) for correctness, quality, security, and performance

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service