Job Requirements
McLean, VA
Top Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Overview
We are seeking a Salesforce Security Engineer to serve as the primary point of contact for security across the Salesforce environment. In this role, you will help strengthen the security posture and reduce security risk across the environment, address security issues and questions raised by internal and external teams, assist Information System Security Officers (ISSOs) in securing their applications, gather security artifacts to support Authorization to Operate (ATO) activities, and build Splunk queries to identify anomalous events.
Contributions
Responsibilities include:
Qualifications
Required
Preferred
About steampunk
Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit http://www.steampunk.com .
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.
We are seeking a Salesforce Security Engineer to serve as the primary point of contact for security across the Salesforce environment. In this role, you will help strengthen the security posture and reduce security risk across the environment, address security issues and questions raised by internal and external teams, assist Information System Security Officers (ISSOs) in securing their applications, gather security artifacts to support Authorization to Operate (ATO) activities, and build Splunk queries to identify anomalous events.
Contributions
Responsibilities include:
- Design, implement, and audit Salesforce access controls (e.g., profiles, permission sets, roles, sharing rules, field-level security), applying least privilege principles across all user populations.
- Conduct periodic access reviews and recertifications to identify and remediate overly permissive or outdated access.
- Configure and maintain Salesforce security settings via the Setup Menu, including but not limited to session settings, login IP ranges/restrictions, password policies, multi-factor authentication (MFA) enforcement, Health Check, Shield Platform Encryption, and Event Monitoring.
- Build and maintain Splunk queries and dashboards to monitor Salesforce login events, permission changes, and anomalous access patterns, and support incident investigations with log analysis.
- Assess and harden web application security for Salesforce Connected Apps, including internet-facing security settings (Cross-Origin Resource Sharing (CORS), Content Security Policy (CSP), Trusted URLs, OAuth/Connected App policies, session security).
- Assist ISSOs in securing their applications and collecting security artifacts in support of their assessment and authorization efforts.
- Partner with system owners and compliance teams to ensure security configurations align with federal security requirements (e.g., NIST 800-53, FedRAMP, as applicable).
- Document security configurations, findings, and remediation steps for audit and ATO support.
- Review and provision privileged user access.
Qualifications
Required
- Ability to obtain and maintain a U.S. Government security clearance.
- Bachelor's degree.
- 8-10 years of experience in Salesforce administration or security engineering.
- Strong knowledge of Salesforce access control models (profiles, permission sets, roles, sharing rules) and least privilege implementation.
- Extensive experience with Salesforce Setup Menu security configuration (session security, login policies, Health Check, Event Monitoring, Shield).
- Proficient in writing Splunk search queries (SPL) for log analysis, monitoring, and alerting.
- Working knowledge of web application security concepts, including internet security settings (CSP, CORS, trusted domains, OAuth flows).
Preferred
- Salesforce Administrator (ADM 201) or Salesforce security-related certification.
- One of the following security certifications: CISSP, CISM, or similar.
- Familiarity with NIST 800-53 security controls.
- Experience supporting federal government clients or ATO processes.
About steampunk
Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit http://www.steampunk.com .
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.
group id: 10150207