Software Engineering MTS
Software Engineering
Bellevue, WA, USA
The Experience
The Authentication Platform team owns the core identity services for Salesforce's production infrastructure — the Production IAM stack. The portfolio spans Kerberos-based authentication, TOTP, and FIDO2/WebAuthn, bridging legacy infrastructure protocols and modern cloud-native identity standards. Because the platform is a tier-0 dependency for the entire company, we run at massive throughput with a 4+ nines availability target across Public Cloud (AWS/GCP) and hybrid deployments on Kubernetes, with modern CI/CD. Our security posture is Zero Trust and least-privilege by default, and we partner closely with security architects on identity verification and credential-handling design.
You'll work on services in the Production IAM stack as an individual contributor — implementing features across the Kerberos, TOTP, and FIDO2/WebAuthn service portfolio, contributing to designs that senior engineers lead, and taking on-call for a tier-0 platform. This is a hands-on engineering role focused on strong execution, growing technical depth in identity protocols, and shipping high-quality, well-tested code in a security-critical environment.
What You'll Actually Be Doing
- Deliver features across the Authentication Platform's service portfolio - Kerberos, TOTP, FIDO2/WebAuthn - writing clean, well-tested backend code in Java, Go, or C#.
- Contribute to design specs and research spikes for features in your area, alongside more senior engineers who lead the design.
- Implement identity and federation protocols used by the platform, including Kerberos, LDAP, WebAuthn/FIDO2, and TOTP. Familiarity with SAML/OIDC is useful for interop conversations with adjacent teams.
- Partner with the Product Owner and tech lead on story-level scope, sequencing, and dependencies for your own work, and help refine and clarify work items before they land in a sprint.
- Reliably deliver as a developer, reviewer, and tester — high test coverage, clean code, and reviews that catch issues before they land, with a security-first mindset appropriate for tier-0 services.
- Apply Salesforce engineering best practices to code, tests, and CI/CD pipelines. Leave code in better shape than you found it.
- Use AI development tools (e.g.Claude Code) in your day-to-day workflow, and critically evaluate both human and AI-generated code for correctness, performance, and security compliance.
- Analyze and fix bugs in your area, working with more senior engineers on the complex ones. Debug production issues and drive them to a fix.
- Exhibit ownership beyond just coding your features — an active role in testing, review, and monitoring is part of the job, especially given the tier-0 nature of the platform.
- Participate in the on-call rotation for the Authentication Platform and handle common alerts confidently. On-call is a real, high-visibility part of this role because of the platform's tier-0 status.
- Understand the platform's telemetry — metrics, logs, traces, SLIs — and extend it for the features you own. The availability target is 4+ nines.
- Contribute to Root Cause Analyses for incidents in your area, and follow through on assigned action items.
- Work with internal stakeholders — service teams and infrastructure owners who depend on the Authentication Platform — to answer integration questions about the features you own.
- Author and maintain technical documentation and runbooks for your work.
You're Our Person If...
- Strong programming ability in Java, Go, or C#, with production experience building backend services.
- Working knowledge of at least one identity or federation protocol from this set: Kerberos, LDAP, WebAuthn/FIDO2, TOTP, SAML, OIDC. Deeper experience in one or more is a plus.
- Experience building, deploying, and debugging distributed services in a Public Cloud environment (AWS or GCP) or a hybrid deployment, using Kubernetes and modern CI/CD.
- Solid grasp of software fundamentals: data structures, testing, code review, source control, CI/CD, and Agile execution as a team member.
- A security-first mindset — writing code with least-privilege defaults, threat-aware reviews, and thorough automated testing appropriate for identity-critical systems.
- Ability to debug production issues in a distributed system using logs, metrics, and traces.
- Comfortable executing an agreed-upon plan largely independently, escalating design-level and cross-cutting decisions to senior engineers.
Even Better If...
- IAM specialist depth — familiarity with the internals of one or more of Kerberos, LDAP, WebAuthn/FIDO2, TOTP, and the interop story with SAML/OIDC.
- Security hardening — familiarity with HSMs, PKI, and secure credential storage patterns.
- Compliance and auditing — exposure to controls and evidence requirements under PCI, SOC 2, or HIPAA.
- Operational grit — experience on-call for a high-visibility production service, and comfort debugging live incidents under pressure.
- Experience integrating AI development tools into engineering workflows, including prompt design and reviewing AI-generated code for security-critical systems.
Education
- Master's degree (or foreign equivalent) in Computer Science, Cybersecurity, Software Engineering, or a related field. A Bachelor's degree (or foreign equivalent) is acceptable with additional years of experience.
Minimum years of experience
- 3 years of software engineering experience