SonicJobs Logo
Left arrow iconBack to search

Salesforce Security Officer

eSimplicity
Posted a month ago, valid for a month
Location

Dhs, MD 20588, US

Salary

$112,800 - $165,400 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • eSimplicity is seeking a Salesforce Security Engineer and System Security Officer (SSO) with a minimum of 8 years of experience in implementing security controls and monitoring compliance for systems.
  • The role involves working within a DevSecOps/SAFe Agile framework, focusing on integrating security into the Agile delivery process.
  • Candidates must possess deep knowledge of Salesforce security architecture and be able to manage end-to-end security processes, including incident response and compliance documentation.
  • A Bachelor's degree in a related field is required, or alternatively, 10 years of general IT experience with at least 8 years of specialized experience may be acceptable.
  • The position offers a competitive salary and full healthcare benefits, with a hybrid working environment and occasional travel for training and project meetings.

Description

About Us:

eSimplicity is modern digital services company that work across government, partnering with our clients to improve the lives and ensure the security of all Americans鈥攆rom soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers and strategist cut through complexity to create intuitive products and services that equip Federal agencies with solutions to courageously transform today for a better tomorrow for all Americans.


Purpose of Scope:

We are seeking a Salesforce Security Engineer and System Security Officer (SSO) with a proven balance of technical security engineering and governance/compliance expertise who is to be responsible for providing security support services while meeting security compliance requirements for a portfolio of systems at various states of maturity and modernization. The SSO is expected to work inside a DevSecOps / SAFe Agile delivery framework and must operate inside an Agile Release Train (ART) alongside DevSecOps, Product Owners, and Engineers. The SSO role is embedded, constantly aligning security with Agile delivery rather than in a detached compliance silo. In this role, the SSO is ultimately a happy mix of DevSecOps engineer, Security Governance Guru and Security Product Owner/Scrum Master that is responsible and accountable for end-to-end ownership of security processes, from design through continuous operation and improvement, across Salesforce GovCloud and AWS environments to include but is not limited to possessing the following capabilities:聽


路 聽Embrace SSO to SAFe Agile Responsibilities, acting as a Security Product Owner/Scrum Master within Agile ceremonies, ensuring security backlog items are identified, refined, and prioritized alongside feature delivery.聽

路 聽Act as the Technical Salesforce Security SME for Federal Government Programs, responsible for designing, implementing, and enforcing security controls across Salesforce Government Cloud (Experience Cloud, Health Cloud) environments

路 聽Act as a hands-on security team engineering/technical lead and a governance champion and subject matter expert, directing technical remediation while capable of actively responding to and maintaining all Authorization to Operate (ATO) requirements.聽

路 聽Serve as the primary liaison for incident response, security inquiries, and compliance reporting to the agency and stakeholders.聽

路 聽Create various communication channels to provide timely and accurate responses to security related data calls (System Security & Compliance Status, Vulnerability and Compliance scanning issues). 聽

路 聽Manage coordination and response to agency security related inquiries, compliance with agency policies, implementation of security controls, and maintenance of security documentation and artifacts.聽

路 聽Provide subject matter expertise throughout the system development lifecycle and interface with multiple stakeholders through multiple touchpoints weekly.聽

路 聽Lead Security Impact Analyses (SIAs), integrate automated security validation into CI/CD pipelines, and ensure tools are configured and tuned for maximum effectiveness.聽

路 聽Drive continuous improvement and automation of security processes, including access control, vulnerability management, and compliance validation; continuously monitoring the cybersecurity posture of systems to secure against cyber threats, and provide security governance, architectural guidance, and enforcement of security controls across the Salesforce and AWS ecosystem.聽

路 聽Direct how security tools, cloud services, and guardrails are implemented by our DevSecOps engineering teams; as well as taking ownership of communication and visualization of security issues especially where coordination between product teams, information owners, engineering and infrastructure staff is necessary for remediation.聽

路 聽Manage end-to-end onboarding/offboarding lifecycle processes, ensuring timely provisioning, least-privilege access enforcement, privileged account management, and periodic reviews.聽

路 聽Build and maintain dashboards and reporting solutions that give leadership and teams visibility into risk, vulnerabilities, and compliance status.聽


Responsibilities:

路 聽Lead Salesforce security reviews for new features and integrations, validating object-level, field-level, record-level access, sharing behaviors, and APIs before production releases

路 聽Design and govern Salesforce access models using Profiles, Permission Sets, Permission Set Groups, Roles, Sharing Rules, and Delegated Administration, ensuring least-privilege and separation of duties

路 聽Manage end-to-end vulnerability management lifecycle from detection to remediation and reporting. Drive identification of new attack vectors and implement automation-driven improvements; configure and operate security tools (Snyk, AppOmni, Tenable, Invicti, Splunk, SecurityHub), to ensure findings are triaged, prioritized, and remediated. 聽

路 聽Champion the integration of automated security testing into the CI/CD pipeline to align with continuous delivery practices. Integrate security controls into CI/CD pipelines (GitHub Actions, Jenkins, Copado, Terraform, Kubernetes).聽

路 聽Build and maintain dashboards in Splunk, Jira, or equivalent tools to report on vulnerabilities, compliance, access reviews, and system posture.聽

路 聽Lead Security Impact Analyses (SIAs) for proposed changes and facilitate the SIA process within Agile cadence, ensuring change reviews don't block delivery but still meet compliance.聽

路 聽Lead incident response activities, from detection through remediation and post-mortem review; conduct log reviews (Splunk), to monitor systems for breaches, and ensure tuning of detection and alerting rules.聽

路 聽Define, enforce, and lead least-privilege access models for Salesforce, CI/CD pipelines, AWS and infrastructure.聽

路 聽Manage end-to-end user lifecycle: onboarding, offboarding, least-privilege enforcement, privileged access reviews, and IAM guardrail enforcement.聽

路 聽Automate identity and access workflows wherever possible and integrate continuous access reviews with reporting dashboards.聽

路 聽Develop automation (Python, Bash, PowerShell, APIs) for onboarding, compliance validation, and recurring security tasks.聽

路 聽Lead compliance interactions as the primary liaison for agency data calls, reviews, and audits; maintain and update all ATO documentation (SSPs, POA&Ms, IRPs, CMPs, PIAs, contingency plans); facilitate tabletop exercises and ensure lessons learned are implemented.聽

路 聽Participate in SAFe Agile Program Increment (PI) Planning, architecture reviews, sprint planning, and backlog refinement to embed security throughout the SDLC providing input on security guardrails, dependencies, and risks that may impact delivery commitments. Clearly communicate security requirements to technical and non-technical audiences.聽

路 聽Drive the reengineering of processes for efficiency and visibility, ensuring leaders and engineers have actionable data. Define and manage security enablers in the program backlog to ensure that architectural runway includes continuous security improvements.聽

路 聽Collaborate with Release Train Engineers (RTEs) to track security risks, impediments, and dependencies across teams; work directly with Scrum Masters and Product Owners to ensure user stories include clear security acceptance criteria; ensure security features and enablers are represented in Definition of Done (DoD) across all product teams.聽

路 聽Mentor product and engineering teams on secure development practices and continuous security; translate and tailor NIST 800-53 Rev 5 and CMS security controls into actionable tasks for DevSecOps teams. Educate Agile teams on secure development practices and evolving threat models, ensuring security becomes part of the team culture.聽

路 聽Review and validate completed user stories and features to confirm security controls have been implemented as designed; continuously measure and report security-related metrics (e.g., backlog burn-down of vulnerabilities, compliance closure rates) during Inspect & Adapt workshops.聽

Requirements

Required Qualifications:

路 All candidates must pass public trust clearance through the U.S. Federal Government. This requires candidates to either be U.S. citizens or pass clearance through the Foreign National Government System which will require that candidates have lived within the United States for at least 3 out of the previous 5 years, have a valid and non-expired passport from their country of birth and appropriate VISA/work permit documentation.

路 聽A Bachelor鈥檚 degree in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline. OR

路 In lieu of a degree, 10 years of general information technology experience and at least 8 years of specialized experience may be substituted.

路 聽Deep, practical knowledge of Salesforce security architecture, including Profiles vs Permission Sets, Permission Set Groups, Sharing Rules, Role Hierarchies, Record-Level Security, and Delegated Administration

路 聽Experience performing security reviews of Salesforce metadata and application logic, including Apex, Flows, and Experience Cloud configurations

路 聽Minimum of 8 years experience implementing security controls and monitoring compliance for systems, in accordance with federal system security and privacy regulations.

路 聽Strong understanding of continuous automated security practices applied to data and application engineering teams.聽

路 聽Demonstrated ability to manage end-to-end security processes, from requirements and configuration through monitoring, reporting, and closure.聽

路 聽Proven hands-on management of user onboarding and offboarding processes, including provisioning, deprovisioning, least-privilege enforcement, privileged account management, and periodic reviews.聽

路 聽Experience with designing security "baked-in" to any architecture: Cloud and IaC, Applications, Web application, Data Processing, Data Centric Applications, AI/ML, CICD Pipelines; seeks automation driven designs.聽

路 聽Demonstrated work experience with computer networking, cryptography, security engineering and architecture, vulnerability assessments, or operating systems as required.聽

路 聽Experience automating onboarding/offboarding workflows and building dashboards (Splunk, Jira, or equivalent) for visibility into access control, vulnerabilities, and compliance posture.聽

路 聽Hands-on configuration and operation of security tools (Snyk, AppOmni, Tenable, Invicti, Splunk, AWS SecurityHub), including integration into CI/CD pipelines.聽

路 聽Strong technical knowledge of Salesforce security best practices (roles, profiles, permission sets, OAuth/MFA, AppOmni).

路 聽Practical experience embedding security into CI/CD pipelines (Copado, GitHub Actions, Jenkins, Terraform, Kubernetes).聽

路 聽Demonstrated ability to lead and document Security Impact Analyses (SIAs) for proposed system and architecture changes.聽

路 聽Experience with CI/CD, defining security decision gates and DevSecOps, including AWS Github Actions and Copado CI/CD聽

路 聽Ability to assist customers and stakeholders with defining appropriate management processes (Responsible for documenting application criticality, privacy, and security impact analysis).聽

路 聽Strong working knowledge of secure SDLC, SAST/DAST/IAST/OAST tools, with ability to both configure and interpret results.聽

路 聽Strong understanding business security practices and procedures; knowledge of current security tools available; hardware/software security implementation; different communication protocols; encryption techniques/tools; familiarity with commercial products; and current Internet technology.聽

路 聽Hands-on scripting and automation skills (Python, Bash, PowerShell, APIs).聽

路 聽Excellent organizational, analytical, and problem-solving skills in a fast-paced DevSecOps environment.聽

路 聽Strong communication skills to brief leadership and collaborate with technical/non-technical teams.聽

路 聽Must possess strong analytical and problem-solving abilities; and strong critical-thinking skills in complex communication environments. 聽

路 聽Strong attention to detail. Required to manage/follow-through of multiple independent tasks, dependencies across intra/inter-project teams.聽

路 聽Demonstrated ability to work independently and as part of a cross-functional team.聽

路 聽Demonstrated ability employing SAFe Agile Responsibilities as a SSO and/or DevSecOps Engineer.聽

路 聽Experience with Atlassian Jira & Confluence聽

路 聽Excellent command of written and spoken English.聽


Desired Qualifications:

路 聽Federal Government contracting work experience聽

路 聽Highly preferred industry certification such as the CISSP, CISM, CRISC, CEH, GIAC, etc.聽

路 聽Cloud Security & Automation certifications such as AWS Certified Security Specialty, AWS Solutions Architect, GIAC Cloud Security (GCSA), and CCSK/CCSP聽

路 聽Highly preferred Salesforce or Developer certifications such as Administrator, Security & Privacy, Platform Developer聽

路 聽Technical / Offensive Security certifications such as OSCP, GPEN, CEH, and GWAPT聽

路 聽Experience with Security Information and Event Management (SIEM) systems (i.e Splunk); DevSecOps & CI/CD: Kubernetes Security (CKS), GitHub Advanced Security, or equivalent聽

路 聽Demonstrated experience facilitating tabletop exercises and embedding lessons learned into continuous improvement cycles.聽

路 聽Experience developing or customizing security automation scripts and compliance dashboards for ongoing reporting to leadership.聽

路 聽Prior experience managing systems in AWS cloud environments, familiarity with AWS Tools and Services.聽

路 聽Strong technical knowledge of AWS cloud security (IAM, GuardDuty, CloudTrail, Security Hub)

路 聽Strong working knowledge of DISA STIGs, CIS Benchmarks, and other hardening standards and strong working knowledge of NIST RMF, NIST 800-53 Rev 5, and FedRAMP requirements.聽

路 聽Experience maintaining and updating ATO documentation (SSPs, POA&Ms, IRPs, CMPs, PIAs, contingency plans).聽

路 聽Experience with Government Agency Security Assessment Process in support of maintaining and/or establishing an ATO and the appropriate security boundary.聽


Working Environment:
eSimplicity supports a hybrid work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager.

Occasional travel for training and project meetings. It is estimated to be less than 25% per year.


Benefits:
We offer highly competitive salaries and full healthcare benefits.


Equal Employment Opportunity:
eSimplicity is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender, age, status as a protected veteran, sexual orientation, gender identity, or status as a qualified individual with a disability.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.