Position Summary
The Senior Salesforce Architect leads the technical vision and the security architecture of our Salesforce environment. This role sits at the intersection of solution design and compliance: every architectural decision has an authorization consequence, and this person is accountable for both. This person will have the Salesforce Developer and Administrator as direct reports.
The candidate must be able to reason natively about control inheritance, boundary management, and the cost of an architectural choice measured in assessment effort as well as engineering effort.
Key Responsibilities
Architecture & Design
- Lead end-to-end solution architecture across Sales Cloud, Service Cloud, Public Sector Solutions, Experience Cloud, and connected systems within the accredited environment.
- Design explicitly against the Government Cloud authorized and interoperable product lists; maintain an internal register of which capabilities are available on our tier and which require risk acceptance.
- Produce and maintain architecture artifacts: logical and physical data models, system landscape diagrams, data flow diagrams (including the authorization boundary drawn on them), and integration sequence diagrams.
- Define org strategy, environment strategy, and the sandbox model — including how non-production environments are provisioned and what data may exist in them.
- Design for large data volumes and long federal retention horizons: indexing, skinny tables, archiving, and NARA-compliant records disposition.
Security Architecture & Authorization
- Responsible for the technical content of the System Security Plan (SSP) sections relating to the Salesforce environment; write and maintain control implementation narratives against NIST SP 800-53 and or NIST SP 800-171
- Serve as the technical lead during 3PAO assessments, agency security reviews, and annual assessments; respond to assessor findings and author remediation plans.
- Create and manage the Plan of Action and Milestones (POA&M) items assigned to the platform; drive them to closure on schedule.
- Govern the authorization boundary: define and enforce the review process for any new package, integration, connected app, or external service, including confirmation of the counterparty's FedRAMP status.
- Design the encryption architecture: Shield Platform Encryption, FIPS-validated cryptography, and key management strategy including Bring Your Own Key or Cache-Only Key Service where the agency requires key custody.
- Design the identity and access architecture: federation to the agency IdP, CAC/PIV and PIV-derived credential authentication, phishing-resistant MFA, and session management aligned to agency policy.
- Design audit and monitoring architecture: Event Monitoring, Setup Audit Trail retention, and log forwarding into the agency SIEM to satisfy continuous monitoring obligations.
Required Qualifications
- 10+ years in enterprise software, with 6+ years architecting Salesforce solutions and 3+ years in a FedRAMP-authorized or equivalently accredited environment.
- Demonstrated experience supporting an ATO: authoring or substantially contributing to SSP control narratives, participating in a 3PAO assessment, and owning POA&M remediation.
- Working fluency in NIST SP 800-53 control families as they apply to a SaaS/PaaS tenantÂ
- Deep expertise in the Salesforce data model, sharing and security model, and platform governor limits.
- Strong hands-on background in Apex, Lightning Web Components, SOQL/SOSL, and Flow — enough to review code and challenge designs credibly.
- Experience with enterprise integration patterns and at least one middleware platform.
- Understanding of Section 508 and WCAG obligations as they constrain solution design.
- Excellent written communication. This role produces documents that auditors read; the writing standard is higher than in commercial work.
- U.S. citizenship and ability to obtain and maintain Top Secret clearance.
Certifications
Required: Salesforce Certified Application Architect or System Architect, or the underlying component certifications (Data Architect, Sharing & Visibility Architect, Integration Architect, Development Lifecycle & Deployment Architect).Â
Strongly preferred: Certified Technical Architect (CTA).Â
Preferred Qualifications
- Prior architecture work on a federal, DoD, or state agency Salesforce program with a named agency reference.
- Experience with Public Sector Solutions, Grants Management, Licensing/Permitting, or Case Management for government.
- Familiarity with Agentforce for Public Sector and the constraints on AI feature adoption in accredited environments.
- Experience with CMMC Level 2 or 3 readiness, IRS 1075, StateRAMP, or CJIS.
#ZR
Learn more about this Employer on their Career Site
