Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Salesforce.com, inc.

Herndon (VA)

Hybrid

USD 111,000 - 122,000

Full time

4 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Salesforce National Security in Northern Virginia seeks a Computer Security Incident Report Analyst with TS/SCI clearance to join the SNS Infrastructure Security Team. This on-site role across SNS Cloud environments focuses on incident response, log analysis, and rapid containment.

The candidate must be a U.S. citizen with Top Secret/SCI clearance with Polygraph, plus a related technical degree or equivalent experience and 2+ years in cybersecurity or incident response.

Qualifications

  • Must be a U.S. citizen with active TS/SCI clearance with Polygraph.
  • Related technical degree or equivalent work experience in CS/SE/Cybersecurity/Information Assurance.
  • 2+ years in cybersecurity, engineering, and/or incident response roles.

Responsibilities

  • Respond to and investigate cybersecurity events within SNS Cloud environments.
  • Track and document security events in a ticketing system; analyze log data for indicators of compromise.
  • Coordinate incident response actions across multi-disciplinary teams to meet SLAs and report to senior leadership.

Skills

Interpersonal skills
Communication
Problem solving
Scripting (Bash/Python)
Threat landscape knowledge

Education

Related technical degree (CS, SE, Cybersec, InfoSec)

Tools

Splunk
Kibana
Grafana
AWS
Azure
GCP
SIEM

Job description

Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Computer Security Incident Response Analyst
This is a customer-facing role and will require you to be on-site in Northern Virginia. This is NOT a remote position.


Salesforce - the leader in enterprise cloud computing and one of the top 10 places to work according to Fortune magazine - is seeking an Incident Response Analyst for our Government Cloud Security Operations team.
As part of the Salesforce National Security (SNS) Infrastructure Security Team, the Incident Response Analyst will work on the ‘front lines’ of Salesforce environments supporting US Government agencies and departments performing national security functions. The Infrastructure Security Team, protects our critical infrastructure and our customers’ data from the latest information security threats. The team is responsible for 24x7x365 security monitoring, security operations, real-time analysis of security alert data, and rapid incident response across SNS Cloud environments.


PLEASE NOTE: Qualification for this job is contingent upon acceptable results from a background investigation as well as your having and maintaining the specific level of U.S. government background investigation and clearance required for this role.


Role Description:
The Incident Response Analyst will respond to and investigate cyber security events within the SNS Cloud environments, track and document security events and incidents in a ticketing system, and analyze log data for signs of malicious activity in a Security Information and Event Manager (SIEM).
The Analyst will need to work across multi-disciplined teams to coordinate incident response actions for high-priority, high-transparency operations security issues to drive toward a resolution while meeting required service-level agreements, escalating as appropriate, and providing regular updates to senior leaders.


This position offers a challenging opportunity to be exposed to a diverse set of security disciplines, including incident response, forensics, reverse engineering, malware analysis, intrusion detection, network security, and system security.
This position provides opportunities to automate workflows and processes, develop new analytics and apply mitigations for adversary Tactics, Techniques, and Procedures (TTPs), and hunt for undetected indicators of compromise.
This position may require you to provide periods of 24x7 on-call support on an as-needed basis.


As we work with Government customers, this position may require occasional local travel to customer sites.
Minimum Qualifications:
The candidate must be a U.S. citizen and must have an active U.S. Government Top Secret/SCI security clearance with Polygraph.

A related technical degree, such as Computer Science, Software Engineering, Cybersecurity, Information Assurance, or equivalent work experience.

2+ yearsexperience in cybersecurity, engineering, and/or incident response roles.

Strong interpersonal and communication skills required for coordinating responses to sophisticated incidents across the organization with many non technical and technical stakeholders.

Strong problem solving ability to determine solutions to encountered or anticipated challenges.

Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.).

Experience with AWS Cloud, Splunk, Azure Sentinel, or ElasticStack, etc. preferred.

Desired Skills:

Technical understanding of the information security threat landscape, to include attack vectors, tools, best practices for securing systems and networks, etc.

Technical understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.).

Familiarity with incident response and security operations within cloud environments.

Familiarity with Mac OSX, Microsoft Windows, and Linux/Unix system administration and security controls.

Technical understanding of AWS, Azure, or GCP administration and security controls.

Experience creating and managing event and metric dashboards with tools like Splunk, Kibana, Grafana, etc.

Experience with data query languages, such as SQL, SPL, GraphQL, etc.

Scripting language (i.e. Bash, Python, etc.) and workflow automation experience.

Operational experience monitoring devices such as network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools, and operating system logs.

System forensics/investigation skills, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise.

Relevant information security certifications, such as CISSP, GCFR, GCIA, GCIH or other related certifications.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.This position requires a USA TS/SCI with Polygraph security access level.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

This position requires a USA TS/SCI with Polygraph security access level.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

Unleash Your Potential

When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.

At Salesforce, we strive to create an accessible and inclusive experience for all candidates.

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodation Request Form .

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates' resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Equal Opportunity Statement.

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that's inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal . Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.

The typical base salary range for this position is $111,000 - $122,000 annually.

The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Salesforce • Herndon (VA)

On-site
USD 111,000 - 122,000
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Salesforce, Inc. • Herndon (VA)

On-site
USD 111,000 - 122,000
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

109 Computable Insights LLC • Herndon (VA)

On-site
USD 111,000 - 122,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Relha LLC • United States

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Socket.dev • McLean (VA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • Bellevue (WA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • McLean (VA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

100 Salesforce, Inc. • McLean (VA)

On-site
USD 149,000 - 224,000
Time off programs
401(k)
Stock purchase program
Security GRC Senior Analyst
Security GRC Senior Analyst

Salesforce • Washington

On-site
USD 117,000 - 177,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Salesforce, Inc. • Bellevue (WA), Northern (KY)

Hybrid
USD 149,000 - 224,000