Senior Incident Responder (CSIRT)

Salesforce

Ireland

On-site

EUR 90,000 - 130,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical Care
Life Insurance
Retirement Savings
Employee Assistance Programs
13 paid days off

Job summary

Salesforce is seeking a Senior Incident Responder for our CSIRT with a passion for information security and strong forensics, incident response and monitoring expertise.

The role is based in the EMEA region with a follow-the-sun schedule and on-call rotation. You will lead investigations, threat hunts and drive improvements to detection, response, and CSIRT tooling to protect data across Salesforce environments.

Qualifications

  • 5+ years of specialised security operations experience.

Responsibilities

  • Participate in technical investigations during security incidents to protect critical infrastructure and customer data.
  • Contribute to threat hunts and enhance detection and incident response capabilities.
  • Improve core CSIRT technologies and processes.
  • Support 24x7x365 security monitoring and rapid incident response.

Skills

SIEM experience
EDR experience
24x7x365 operations
Threat hunting
Incident investigation
Automation / scripting
Cloud security
Communication skills
On-call readiness
DFIR tools

Education

Security certifications (OSCP, SANS GCIH, GCIA, GCFA, GCFE, GX-IH, GX-FA)

Tools

Splunk
Google Security Operations
Microsoft Sentinel
CrowdStrike
Cybereason
Security Service Edge

Job description

  • Salesforce is seeking a Senior Incident Responder for our Cyber Security Incident Response Team (CSIRT) with a passion for Information Security and a strong understanding of digital forensics, incident response and security monitoring
  • The CSIRT is responsible for 24x7x365 security monitoring and rapid incident response across all Salesforce environments. We are the ‘tip of the spear’ and the last line of defense protecting company and customer data from our adversaries
  • This position is based in our EMEA region and working hours correspond to our “follow the sun” operating model and shift according to daylight savings during the year. You are required to do on-call as part of a regular rotation
  • The Senior Incident Responder will participate in technical investigations during security incidents to protect critical infrastructure and our customers’ data from the latest information security threats. You will be contributing to significant strategic projects, conducting threat hunts, enhancing detection and incident response capabilities, and improving core CSIRT technologies and processes
Benefits
  • Medical Care
  • Life Insurance
  • Retirement Savings
  • Employee Assistance Programs
  • With 9 standard holidays and four floating holidays, you get a total 13 paid days off each year
  • Minimum 5+ years of prior specialised security operations experience
  • Operational experience with security incident and event management (SIEM) solutions (i.e. Splunk, Google Security Operations, Microsoft Sentinel, etc)
  • Operational experience performing incident response with Endpoint Detection and Response (EDR) solutions (i.e. Crowdstrike, Cybereason, etc)
  • Operational experience responding to cybersecurity incidents in a production environment, including technical investigations, containment and remediation on large scale network compromises
  • Operational experience with monitoring devices (such as Security Service Edge solutions, network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools)
  • Familiarity with core concepts of security incident response and the security threat landscape (i.e. incident response phases, attack vectors, threat actors, vulnerabilities, IoCs, TTPs)
  • The willingness to apply yourself to learning new skills
  • Understanding of operating system fundamentals and common DFIR tools and artifacts in macOS, Microsoft Windows, and/or Linux/Unix (file system, memory, running processes, network connections)
  • Understanding of incident response and security operations within public cloud environments (i.e. AWS, Azure, GCP)
  • Flexibility, drive, integrity, and creative problem-solving skills
  • Understanding of network fundamentals and common protocols (i.e. HTTPS, DNS, SMTP)
  • Customer-centric attitude and focus on providing best-in-class service for customers and stakeholders
  • The ability to build strong relationships with peers both internal and external to your functional group, and with peers/professional organisations outside the company
  • Experience with scripting, workflow automation or agentic AI capabilities
  • Strong verbal and written communication skills; ability to communicate effectively and clearly to both technical and non-technical audiences
  • Prior experience in a 24x7x365 operations environment
  • Working proficiency with programming or scripting languages (e.g. Python, Bash, Go, PowerShell)
  • Ability to develop custom threat detection rules (i.e. YARA/IDS signatures)
  • Working knowledge of malware reverse engineering
  • Relevant information security certifications, such as: OSCP, SANS GCIH, GCIA, GCFA, GCFE, GX-IH, GX-FA and other related certifications
  • Actively involved in the security community
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior CSIRT Incident Responder — Lead 24/7 Cyber Defense
Senior CSIRT Incident Responder — Lead 24/7 Cyber Defense

Salesforce, Inc. • Dublin

Hybrid
EUR 90,000 - 125,000
Senior Incident Responder, CSIRT - 24x7 Security
Senior Incident Responder, CSIRT - 24x7 Security

Salesforce • Ireland

On-site
EUR 90,000 - 130,000
Medical Care
Life Insurance
Retirement Savings
+2
Senior Incident Responder, CSIRT
Senior Incident Responder, CSIRT

Salesforce, Inc. • Dublin

Hybrid
EUR 90,000 - 125,000
Senior Incident Responder, CSIRT
Senior Incident Responder, CSIRT

Salesforce • Dublin

On-site
EUR 120,000 - 180,000
Incident Response Manager - Security
Incident Response Manager - Security

United States Digital Space LLC • Dublin

Hybrid
EUR 90,000 - 120,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Realtime Recruitment • Ireland

On-site
EUR 111,000 - 166,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Realtime Recruitment • Dublin

Hybrid
EUR 70,000 - 110,000
Senior Incident Responder: Lead IR & Threat Hunting
Senior Incident Responder: Lead IR & Threat Hunting

Salesforce • Dublin

On-site
EUR 120,000 - 180,000
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Dublin

On-site
EUR 90,000 - 120,000
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)
Assoc. Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Dublin

On-site
EUR 120,000 - 180,000