Incident Responder

Salesforce

Virginia (MN)

On-site

USD 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Salesforce is seeking an Incident Responder to join our Global CSIRT. The role provides around-the-clock security monitoring and rapid incident response across Salesforce environments, operating from a 24x7 operations center with shift work, including on-call and weekends.

You will triage alerts, assist containment and recovery, collaborate across teams, and document findings with clear incident notes. US citizenship and the ability to pass a Moderate Public Trust background investigation are

Qualifications

  • 2+ years in IT operations or 1+ year in security operations.
  • Foundational knowledge of information security, threats, networks, and common protocols.
  • Must be able to obtain a Moderate Public Trust background investigation for a US government role.

Responsibilities

  • Perform CSIRT Tier 1 monitoring around the clock, triaging and prioritizing security alerts.
  • Support containment, eradication, and recovery during incidents according to playbooks and guidance from senior staff.
  • Collaborate with engineering, business, and security teams to coordinate response efforts and drive security improvements.
  • Document findings clearly and maintain accurate incident notes and summaries throughout the response process.

Skills

IT operations
Security operations
Incident response

Education

CompTIA Security+
SANS GCFA
GCIH
CS/Cybersecurity degree

Tools

Intrusion detection/response tools
WAFs
Firewalls
Proxies
Antivirus
File integrity monitoring
OS logs

Job description

Job Category

Enterprise Technology & Infrastructure

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Job Description:
The Experience

Salesforce is seeking an Incident Responder to join our Computer Security Incident Response Team (CSIRT). The CSIRT provides around-the-clock security monitoring and rapid incident response across all Salesforce environments, acting as the last line of defense protecting company and customer data from security threats. As a key member of the Global CSIRT, you'll help protect Salesforce's critical infrastructure and customer data from evolving threats. This role operates from our 24x7 operations center and requires shift work, including on-call shifts and weekends.

What You'll Actually Be Doing
  • Perform CSIRT's Tier 1 monitoring function around the clock, triaging and prioritizing security alerts to identify threats requiring escalation.
  • Support containment, eradication, and recovery efforts during security incidents, following established playbooks and guidance from senior team members.
  • Collaborate with engineering, business, and security teams to coordinate response efforts and drive organizational security improvements.
  • Document findings clearly and keep stakeholders informed with accurate incident notes and summaries throughout the response process.
You're Our Person If...
  • You have 2+ years of experience in an IT operations environment, or 1+ years of specialized security operations experience.
  • You have foundational knowledge of information security, including current threats, best practices, network fundamentals, and common internet protocols (DNS, HTTP, HTTPS/TLS, SMTP).
  • You understand operating system administration and security controls for macOS, Microsoft Windows, and Linux/Unix, along with core concepts of incident response (phases of response, vulnerabilities vs. threats vs. actors, and Indicators of Compromise).
  • You're able to build strong working relationships across internal and external teams, and hold U.S. citizenship (born or naturalized, no dual citizenship) with the ability to pass a Minimum Background Investigation for a Moderate Public Trust position with the U.S. federal government.
Even Better If...
  • You have hands-on experience with security infrastructure such as intrusion detection/response tools, WAFs, firewalls, proxies, antivirus, file integrity monitoring, and OS logs.
  • You have an in-depth understanding of the information security threat landscape, including attack vectors, tools, and best practices.
  • You've contributed to cross-functional, global security projects and enjoy continuously learning new skills and processes.
  • You hold relevant certifications (e.g., CompTIA Security+, BTL1, SANS GCFA, GCIH) or have a degree in Computer Science, Cybersecurity, or a related field, plus foundational understanding of GenAI, Agentic AI, and prompt engineering.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Unleash Your Potential

When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best , and our AI agents accelerate your impact so you can do your best . Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form .

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates' resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Posting Statement

Salesforce is an equal opportunity employer and maintains

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Responder
Incident Responder

100 Salesforce, Inc. • McLean (VA)

On-site
USD 96,000 - 145,000
Time off
Medical coverage
Dental coverage
+7
Incident Responder
Incident Responder

salesforce.com, inc. • McLean (VA)

On-site
USD 96,000 - 145,000
Incident Responder
Incident Responder

salesforce.com, inc. • Bellevue (WA)

On-site
USD 96,000 - 145,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • Bellevue (WA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • McLean (VA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Socket.dev • McLean (VA)

On-site
USD 149,000 - 224,000
Lead, Incident Response - Global CSIRT
Lead, Incident Response - Global CSIRT

salesforce.com, inc. • McLean (VA)

On-site
USD 173,000 - 260,000
Lead, Incident Response - Global CSIRT
Lead, Incident Response - Global CSIRT

salesforce.com, inc. • Bellevue (WA)

On-site
USD 173,000 - 260,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Salesforce, Inc. • Bellevue (WA), Northern (KY)

Hybrid
USD 149,000 - 224,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Salesforce, Inc. • United States

On-site
USD 173,000 - 260,000