We are seeking an experienced Salesforce Security & Identity SME to work closely with Cyber Security and Salesforce Application teams to strengthen security controls across the Salesforce environment.
The role will focus on Salesforce security hardening, vulnerability remediation, identity and access management, data protection, and security monitoring. You will assess existing security findings and work with technical and business stakeholders to implement practical remediation and enhanced security controls.
Location: Melbourne
Role type: 3 days in the office
Duration: 6 month contract
Key Responsibilities
- Work with Cyber Security and Salesforce Application teams to prioritise and remediate findings from security health checks.
- Assess, prioritise and remediate Salesforce vulnerabilities identified through AppOmni or similar SaaS security platforms.
- Strengthen Salesforce authentication and access controls, including Multi-Factor Authentication (MFA).
- Implement and maintain least-privilege access based on user role and business function.
- Configure and enhance Salesforce data security controls to reduce the risk of unauthorised access or bulk data extraction.
- Review and implement appropriate login IP restrictions and access policies.
- Conduct security reviews of Connected Apps and OAuth configurations.
- Review and strengthen API and integration security patterns.
- Configure and review Salesforce access controls, including Organisation-Wide Defaults (OWD), profiles and permission sets.
- Support improvements to security monitoring,
alerting and overall visibility across the Salesforce setting.
- Maintain clear documentation of security findings, remediation activities, controls and decisions.
- Proactively identify and communicate security risks, issues and remediation options.
Required Skills & Experience
- Strong hands-on experience in Salesforce security and identity/access management.
- Demonstrated experience with Salesforce platform and organisation hardening.
- Strong knowledge of Salesforce authentication, authorisation and access control models.
- Experience configuring OWD, profiles, permission sets and least-privilege access.
- Strong understanding of MFA and identity security controls.
- Experience reviewing Connected Apps, OAuth and API/integration security.
- Understanding of Salesforce data protection and access security.
- Experience undertaking vulnerability assessment and remediation within Salesforce environments.
- Exposure to AppOmni or similar SaaS security/vulnerability management platforms would be highly regarded.
- Strong stakeholder management skills with the ability to work across Cyber Security and Salesforce/Application teams.
- Confident using JIRA, Confluence, Microsoft Office and process-modelling tools such as Visio.
Certifications
Candidates should ideally hold one or more of the following:
- Salesforce Certified Platform Identity and Access Management Architect, or
- Salesforce Certified Administrator
Additional Salesforce architecture or security certifications would be highly regarded.
If you are interested in this role, click apply today!!