Software Engineering SMTS, Identity and Access Management
Salesforce · India - Hyderabad
Free to search · AI fit score against your CV · tailor your résumé in one click
Salesforce · India - Hyderabad
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Software Engineering Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. Software Engineering SMTS, Identity & Access Management About the teamThe Salesforce Enterprise Security Engineering team builds and operates highly scalable, fault-tolerant, distributed systems that deliver cloud-scale Identity and Access Management (IAM) services across our Enterprise network, public cloud infrastructure, and internal data centers. We provide the core building blocks for identity lifecycle, governance, authentication, authorization and privileged access management that protect customer trust and empower every Salesforce engineer to operate securely, regardless of environment. We are seeking a full-stack software engineer with a track record of building modern, secure services and applications following the Software Development Life Cycle and best security development practices. You'll work across the IAM domain, so a solid understanding of identity concepts in the authentication, authorization, and identity governance space is important for this role. About the positionThis is a hands-on software engineering role with a focus on the IAM domain. You will design and build end-to-end capabilities from backend services and APIs to the user-facing experiences that power identity lifecycle (human/non-human), access requests, provisioning, entitlement/role management, access certifications, and policy-driven access decisions at enterprise scale.You will secure the emerging agentic enterprise by designing controls for AI agents and autonomous workloads, including agent identity, privilege, least privilege, just-in-time access, time-bound access, separation of duties, and continuous risk-based access decisions. You will also own features through the full development lifecycle: design, implementation, testing, deployment, and continuous improvement. You'll partner across application owners, product management, and governance to translate identity and compliance requirements into intuitive, reliable, and scalable solutions. This work is foundational to advancing Salesforce's Zero Trust architecture, enabling dynamic, real-time access decisions based on employment status, role change, and device or user trust. ResponsibilitiesDesign, build, and operate scalable IAM services and APIs spanning identity lifecycle, access requests, entitlement/role management and access certifications.Build privileged access management (PAM) capabilities — credential vaulting/rotation, session control, and secrets management and just-in-time (JIT) access flows that grant elevated, time-bound entitlements and revoke them automatically.Model and secure non-human/workload identities (NHI) — service accounts, agents, workloads, and machine credentials — including issuance, rotation, and lifecycle governance.Develop full-stack features, backend services and modern web front-ends that deliver intuitive self-service and administrative experiences for IAM.Build and manage containerized workloads with Kubernetes, Docker, and infrastructure-as-code (Terraform); operate services in a full DevOps model (monitor, troubleshoot, continuously improve).Integrate across identity sources, directories, and downstream applications using SCIM, REST, and event-driven patterns.Partner with governance and compliance teams to embed SoD, least-privilege, and audit controls (SOX, NIST, SOC 2) into the platform.Write clean, maintainable, secure code; participate in design and code reviews; and champion secure SDLC practices.Collaborate with cross-functional teams across security, infrastructure, product, and engineering to ensure platform integrity and trustworthiness.Create and maintain technical documentation, runbooks, and enablement materials.Design for significant features, mentor junior engineers, and drive technical direction and continuous improvement across the platform. Required Skills/Experience SMTS: 5+ years of professional software development experience building distributed systems in SaaS, PaaS, or IaaS environments.Full-stack development proficiency: strong backend skills in Java, Go, and/or Python, plus front-end experience with modern frameworks (e.g., React).Solid understanding of the IAM domain, identity governance/lifecycle, authentication, authorization, RBAC/entitlement models, privileged access management including just-in-time access and common protocols (OAuth2, OIDC, SAML, SCIM, LDAP).Experience designing and consuming REST APIs (JSON/XML, OpenAPI/Swagger) and integrating heterogeneous systems.Strong experience on public cloud platforms (AWS/Azure/GCP), including containers (