Software Engineering PMTS
Software Engineering
San Francisco, CA, USA
Posted on Oct 8, 2026
The Team
Our team owns the defensive security of Salesforce Database — the production database system behind Salesforce's cloud platform, including its storage layer, backup and restore systems, and telemetry and operational infrastructure — storing customer data at a scale and criticality that few systems in the world match.
AI has changed the threat landscape: agents opened new production entry points, automated adversarial attacks demand instant response, and vulnerabilities must be addressed in hours. We are building the next-generation defense system for that reality: detection, compliance enforcement, agent security guardrails, and vulnerability management — it runs continuously and acts without waiting on manual review. This role is core to that effort.
What You'll Do
You will own the design and hands-on implementation of security software that keeps SDB secure and compliant. Your work will span:
What We're Looking For
This role requires 10+ years of professional experience. Experience with large-scale distributed databases or multi-tenant SaaS architectures is a strong plus.
Our team owns the defensive security of Salesforce Database — the production database system behind Salesforce's cloud platform, including its storage layer, backup and restore systems, and telemetry and operational infrastructure — storing customer data at a scale and criticality that few systems in the world match.
AI has changed the threat landscape: agents opened new production entry points, automated adversarial attacks demand instant response, and vulnerabilities must be addressed in hours. We are building the next-generation defense system for that reality: detection, compliance enforcement, agent security guardrails, and vulnerability management — it runs continuously and acts without waiting on manual review. This role is core to that effort.
What You'll Do
You will own the design and hands-on implementation of security software that keeps SDB secure and compliant. Your work will span:
- Designing security detection and enforcement software for large-scale production database systems
- Building static and dynamic analysis pipelines for database vulnerability classes: SQL injection, privilege escalation, broken access control, and tenant-isolation breaches
- Applying ML to anomaly detection: data exfiltration, insider threat, and unusual access to customer data
- Building security guardrails for AI agents and LLMs operating on production databases: least-privilege configuration, scoped API access, sandbox isolation, and runtime behavioral monitoring
- Shipping automation for real-time detection and response to fast, automated attacks
- Driving vulnerability management and software composition analysis across the database platform
- Partnering with database engineering teams to embed security into the platform, from design review through production rollout
What We're Looking For
- Deep understanding of database security, including multi-tenant isolation, access control, and data governance
- Experience leading threat modeling and architecture risk analysis for complex distributed database cloud environments
- Expert-level design of consistent security policies across AWS and GCP, including mitigating provider-specific edge cases
- Solid grasp of distributed systems and strong programming skills (Python / Rust / Go)
- Hands-on experience building or improving security detection and enforcement software for large-scale production database systems
- A track record of shipping and operating production software at scale, with a preference for direct delivery over writing specifications
- Strong written and verbal communication skills; able to lead security discussions across engineering teams and gain buy-in without formal authority
This role requires 10+ years of professional experience. Experience with large-scale distributed databases or multi-tenant SaaS architectures is a strong plus.