Security Software Engineer, Principal; Platform Trust Intelligence & Security Platform
Listed on 2026-06-18
-
Software Development
AI Engineer (Applied/Software), DevOps
Job Category
Software Engineering
About SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
TheExperience
We are seeking a Principal Software Engineer to join our Platform Trust Intelligence and Security (PTIS) team - the runtime substrate that detects, isolates, and contains threats across an enterprise pivoting to autonomous AI. As organizations deploy AI agents that execute multi-step reasoning, access sensitive data, and take real-world actions, a new class of security risk emerges. Agents operating outside their intended scope can exfiltrate data, probe permission boundaries, or trigger privileged operations at a speed and scale no human user can match - while appearing to function exactly as designed.
This is a hands‑on principal role at the intersection of platform engineering, secure runtimes, and applied machine learning (ML). With Agentforce woven into every layer of our platform, our engineers build intelligent systems that automate the repetitive, elevate the strategic, and power better decisions will lead technical strategy for sandboxed agent execution, real‑time behavioral detection, and policy‑driven response orchestration - all under enterprise constraints including multi‑tenant isolation, regulatory compliance, customer‑trust Service Level Agreements (SLAs), and reversibility on every action that touches a customer's runtime.
This role is based in Bellevue, Washington and is Office Tech‑Flexible (hybrid work environment).
What You’ll Actually Be Doing- Build and ship high‑quality, production‑grade software using modern engineering practices, with AI as a core part of your development workflow - pushing the boundaries of AI development tools to deliver secure, optimized, and high‑quality code.
- Design and orchestrate complex systems where AI agents integrate seamlessly into human workflows, driving efficiency and innovation tribute to building and maintaining shared system context – an explicit repository of system designs, constraints, and standards that enables AI to operate accurately and reliably. Critically evaluate code (human‑ or AI‑generated) for correctness, quality, security, and performance.
- Own the secure execution substrate for AI agents – the layer that turns “the agent wants to run code, call a tool, or touch a file” into a strongly bounded operation with a known blast radius.
- Design and operate microVM‑based isolation using technology stacks like Firecracker for high‑density, fast‑boot agent sandboxes; benchmark against Kata Containers for VM‑grade isolation under a Kubernetes‑native operational model, and choose the right tool per workload (latency‑sensitive tool calls vs. long‑running code‑interpreter sessions vs. third‑party tool execution).
- Integrate and extend E2B‑style code‑interpreter sandboxes for agent code execution: file system snapshotting, network‑egress allow‑listing, per‑session lifecycle, and secure artifact return.
- Implement tiered autonomy at the infrastructure layer – defining which actions an agent may take automatically, which require human approval, and which are categorically denied and enforced below the agent, so a compromised or jail‑broken agent cannot opt out of the rule.
- Build the capability model: per‑agent, per‑tool credential scoping, ephemera identity issuance, egress policy, syscall filtering, and process isolation – so a single agent’s failure can never escape into a tenant‑wide or fleet‑wide incident.
- Treat the sandbox itself as a threat surface: partner with offensive security to red‑team escapes, side channels, and tool‑abuse patterns, and design for graceful failure.
- Build the runtime detection layer that scores agent behavior against learned baselines – detecting bulk data…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).