Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Salesforce in Northern Virginia seeks an on-site Computer Security Incident Response Analyst to join the SNS Infrastructure Security Team. You will respond to cyber security events in SNS Cloud environments, document incidents in ticketing systems, and analyze SIEM logs to detect threats.
The role requires U.S. citizenship and an active Top Secret/SCI clearance with Polygraph. Some on-call and occasional travel may be required.
Software Engineering
Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
This is a customer-facing role and will require you to be on-site in Northern Virginia. This is NOT a remote position.
Salesforce - the leader in enterprise cloud computing and one of the top 10 places to work according to Fortune magazine - is seeking an Incident Response Analyst for our Government Cloud Security Operations team.
As part of the Salesforce National Security (SNS) Infrastructure Security Team, the Incident Response Analyst will work on the 'front lines' of Salesforce environments supporting US Government agencies and departments performing national security functions. The Infrastructure Security Team, protects our critical infrastructure and our customers' data from the latest information security threats. The team is responsible for 24x7x365 security monitoring, security operations, real-time analysis of security alert data, and rapid incident response across SNS Cloud environments.
PLEASE NOTE: Qualification for this job is contingent upon acceptable results from a background investigation as well as your having and maintaining the specific level of U.S. government background investigation and clearance required for this role.
The Incident Response Analyst will respond to and investigate cyber security events within the SNS Cloud environments, track and document security events and incidents in a ticketing system, and analyze log data for signs of malicious activity in a Security Information and Event Manager (SIEM).
The Analyst will need to work across multi-disciplined teams to coordinate incident response actions for high-priority, high-transparency operations security issues to drive toward a resolution while meeting required service-level agreements, escalating as appropriate, and providing regular updates to senior leaders.
This position offers a challenging opportunity to be exposed to a diverse set of security disciplines, including incident response, forensics, reverse engineering, malware analysis, intrusion detection, network security, and system security.
This position provides opportunities to automate workflows and processes, develop new analytics and apply mitigations for adversary Tactics, Techniques, and Procedures (TTPs), and hunt for undetected indicators of compromise.
This position may require you to provide periods of 24x7 on-call support on an as-needed basis.
As we work with Government customers, this position may require occasional local travel to customer sites.