Senior Salesforce Security Engineer

Buchanan Technologies — Canada · Posted ~2 hours ago

Senior Contract Hybrid

Skills

Salesforce security security assessment security governance security monitoring Salesforce configuration Salesforce cloud security

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineering role providing expertise in securing enterprise business platforms. Responsibilities include assessments, governance improvements, monitoring, and remediation planning.

Highlights

Hybrid contract opportunity focused on enterprise security strategy, platform governance, and improving security posture in complex environments.

Description

SENIOR SALESFORCE SECURITY ENGINEER Location: Brampton, Ontario Work Arrangement: Hybrid – minimum two days onsite per week Contract Term: October 2026 to October 2027 Hours: 35 hours per week Extension Option: Up to two additional 12-month terms POSITION OVERVIEW Our client is seeking an experienced Senior Salesforce Security Engineer to provide strategic guidance and hands-on security expertise across the design, configuration, deployment, and optimization of enterprise Salesforce capabilities. The successful consultant will help establish a comprehensive Salesforce security and governance framework, conduct platform security assessments, implement continuous security monitoring, and develop prioritized remediation strategies. This role requires extensive experience delivering secure Salesforce solutions within complex enterprise environments. KEY RESPONSIBILITIES Salesforce Security and Governance Conduct a comprehensive Salesforce security posture and platform health assessment. Identify configuration, access-control, architecture, integration, vulnerability, privacy, and compliance gaps. Develop prioritized remediation strategies and a practical security improvement roadmap. Update and enhance Salesforce security standards using Secure by Design principles. Establish security governance practices aligned with Salesforce and organizational cybersecurity standards. Implement or optimize code-scanning and configuration-scanning tools. Establish continuous security monitoring, auditing, and vulnerability-management processes. Security Controls Review, assess, and optimize: Profiles Permission sets and permission set groups Roles and role hierarchies Sharing rules Organization-wide defaults Field-level security Record-level security Login policies Session controls Multi-factor authentication Salesforce Shield controls Identity and Integration Security Review Salesforce authentication, authorization, federation, and enterprise identity integrations. Secure IAM capabilities involving OAuth, SAML, SSO, federation, and MFA. Assess integration security and recommend improvements. Establish secure API integration standards and protocols. Secure Development and DevSecOps Enforce secure coding standards for Apex and Lightning Web Components. Conduct static code analysis and security reviews of internally and externally developed code. Assess existing software development lifecycle practices and recommend security improvements. Integrate security controls into DevOps and SDLC processes. Compliance and Collaboration Support applicable regulatory, privacy, audit, and organizational security requirements. Collaborate with cybersecurity, IT solutions, platform administration, development, and audit teams. Provide expert guidance on Salesforce security best practices and emerging capabilities. Mentor internal technical and business teams. Deliver documentation, training, and knowledge transfer. MANDATORY QUALIFICATIONS University or college education in Computer Science, Engineering, Information Security, or a related discipline. Minimum five years of experience designing, implementing, and supporting Salesforce solutions in enterprise environments. Minimum five years of hands-on Salesforce solution architecture experience with responsibility for end-to-end delivery. Experience delivering at least three enterprise Salesforce implementations involving complex business processes and integrations. Demonstrated experience designing, implementing, and optimizing Salesforce security models and controls. Hands-on experience integrating and configuring Salesforce Shield. Experience conducting Salesforce security assessments, vulnerability reviews, risk analysis, and remediation planning. Advanced knowledge of secure Apex and Lightning Web Component development. Experience with static code-analysis tools and reviewing third-party or vendor-developed code. Experience implementing DevOps and secure SDLC methodologies. Strong Salesforce Identity and Access Management experience, including OAuth, SAML, SSO, federation, and MFA. Strong technical security-audit and compliance expertise. Strong communication, documentation, mentoring, and knowledge-transfer skills. PREFERRED CERTIFICATIONS SDLC Foundation Certificate or higher Salesforce Certified Application Architect Salesforce Certified Integration Architecture Designer ADDITIONAL INFORMATION The consultant must be available for the full assignment. A minimum of two onsite workdays per week is mandatory. The first and final contract days must be attended onsite for onboarding and offboarding. Occasional travel between nearby client locations may be required. Proof of applicable certifications may be requested. The consultant will work seven hours per day and 35 hours per week, with a one-hour unpaid lunch.