Jobs / United States / Salesforce INC
Platform Security Architect
Salesforce INC · 🇺🇸 Indiana - Indianapolis
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Salesforce INC paid sponsored hires in similar roles1 certified filing for “Security Platform Architect Director” (Information Security Analysts) in VA: $253k–$253k, median $253k. Most were filed at wage level IV (100%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Salesforce INC
The US Department of Labor certified 1,544 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 498 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Salesforce INC →
About the role
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Customer Success Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. The Opportunity: The Platform Guardian We are seeking a Salesforce Platform Expert who specializes in security implementation. You are not just a compliance officer; you are a builder. You understand the Salesforce metadata API better than anyone, you know the limits of Apex Managed Sharing, and you know exactly which "Session Settings" break the user experience if configured incorrectly. In this role, you will be the bridge between our security requirements and the technical reality of the Salesforce platform. You will use your deep platform expertise to architect, configure, and implement the controls that keep our ecosystem secure without sacrificing performance or agility. Role Summary The Salesforce Platform Security Architect is responsible for the hands-on design and implementation of security controls within the Salesforce org. You will own the technical configuration of Sharing & Visibility, Shield Encryption, and Identity flows. You will work alongside developers and admins to ensure that every Flow, Apex Class, and Integration is built securely from the ground up. You translate abstract security policies (e.g., "Least Privilege") into concrete Salesforce configurations (e.g., "Permission Set Groups" and "Field Level Security"). Key Responsibilities Platform Security Implementation (The "Hands-On" Work) • Sharing Architecture: Design and implement complex sharing models. Optimize Org-Wide Defaults (OWD), Sharing Rules, Account Teams, and Territory Management to ensure strict data segregation. • Shield Implementation: Lead the technical deployment of Salesforce Shield. Manage Tenant Secrets, define encryption policies for standard/custom fields, and configure Field Audit Trails to meet retention policies. • Identity Configuration: Configure and troubleshoot SSO (SAML/OIDC), Connected Apps, and Login Flows. managing certificates and Key Management (BYOK) where applicable. Event Monitoring & Detection • Real-Time Monitoring: Build Transaction Security Policies (using Apex or Low-Code) to block data exfiltration attempts in real-time. • Log Analysis: Configure Event Monitoring to export logs to our SIEM (Splunk/New Relic). Create dashboards to visualize login anomalies and report exports. Secure Development Lifecycle (SDLC) • Code Security: Act as the "Security Gatekeeper" for deployments. Review Apex and LWC code for common vulnerabilities (SOQL Injection, XSS, Enforcing Sharing). • DevOps Integration: Configure static code analysis tools (e.g., PMD, Checkmarx, Clayton) within our CI/CD pipeline (Copado/Gearset/Jenkins) to auto-reject insecure code. Connected App & OAuth Governance (Critical Focus) • OAuth Flow Architecture: Select and implement the correct OAuth flows for specific use cases (e.g., JWT Bearer Flow for server-to-server integration vs. Web Server Flow for user-facing apps vs. Device Flow for IoT). • Scope Management: Enforce the principle of Least Privilege by meticulously defining and a