We are seeking a Salesforce Security Engineer and System Security Officer (SSO) with a proven balance of technical security engineering and governance/compliance expertise who is to be responsible for providing security support services while meeting security compliance requirements for a portfolio of systems at various states of maturity and modernization. The SSO is expected to work inside a DevSecOps / SAFe Agile delivery framework and must operate inside an Agile Release Train (ART) alongside DevSecOps, Product Owners, and Engineers. The SSO role is embedded, constantly aligning security with Agile delivery rather than in a detached compliance silo. In this role, the SSO is ultimately a happy mix of DevSecOps engineer, Security Governance Guru and Security Product Owner/Scrum Master that is responsible and accountable for end-to-end ownership of security processes, from design through continuous operation and improvement, across Salesforce GovCloud and AWS environments to include but is not limited to possessing the following capabilities: · Embrace SSO to SAFe Agile Responsibilities, acting as a Security Product Owner/Scrum Master within Agile ceremonies, ensuring security backlog items are identified, refined, and prioritized alongside feature delivery. · Act as the Technical Salesforce Security SME for Federal Government Programs, responsible for designing, implementing, and enforcing security controls across Salesforce Government Cloud (Experience Cloud, Health Cloud) environments · Act as a hands-on security team engineering/technical lead and a governance champion and subject matter expert, directing technical remediation while capable of actively responding to and maintaining all Authorization to Operate (ATO) requirements. · Serve as the primary liaison for incident response, security inquiries, and compliance reporting to the agency and stakeholders. · Create various communication channels to provide timely and accurate responses to security related data calls (System Security & Compliance Status, Vulnerability and Compliance scanning issues). · Manage coordination and response to agency security related inquiries, compliance with agency policies, implementation of security controls, and maintenance of security documentation and artifacts. · Provide subject matter expertise throughout the system development lifecycle and interface with multiple stakeholders through multiple touchpoints weekly. · Lead Security Impact Analyses (SIAs), integrate automated security validation into CI/CD pipelines, and ensure tools are configured and tuned for maximum effectiveness. · Drive continuous improvement and automation of security processes, including access control, vulnerability management, and compliance validation; continuously monitoring the cybersecurity posture of systems to secure against cyber threats, and provide security governance, architectural guidance, and enforcement of security controls across the Salesforce and AWS ecosystem. · Direct how security tools, cloud services, and guardrails are implemented by our DevSecOps engineering teams; as well as taking ownership of communication and visualization of security issues especially where coordination between product teams, information owners, engineering and infrastructure staff is necessary for remediation. · Manage end-to-end onboarding/offboarding lifecycle processes, ensuring timely provisioning, least-privilege access enforcement, privileged account management, and periodic reviews. · Build and maintain dashboards and reporting solutions that give leadership and teams visibility into risk, vulnerabilities, and compliance status.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level