Lead Incident Responder, CSIRT

salesforce.com, inc.

Virginia (IL)

On-site

USD 173,000 - 260,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Salesforce is seeking a Lead Incident Responder for the GovCloud CSIRT. The role requires protecting data across Salesforce environments with 24x7x365 security monitoring and rapid incident response, focusing on FedRAMP environments.

On-call work including evenings and weekends is required, with core hours 10:30 AM - 6:30 PM EST, Monday through Friday. This position sits within the AMERS CSIRT, supporting US GovCloud, with a strong emphasis on cross-functional collaboration, automation, and

Qualifications

  • 8+ years of experience in information security and incident response.
  • Strong system forensics and investigation skills across Windows, Mac OS X, and Linux.

Responsibilities

  • Manage the response to high-severity security incidents and act as a technical escalation point for the Incident Responder team.
  • Lead cross-functional response to high-priority security issues, including insider investigations, advanced adversaries, and web application attacks.
  • Drive process improvement and automation for detection and incident response capabilities.
  • Lead strategic projects that enhance detection and response capabilities within the environment.

Skills

Information security
Incident response
Forensics
Cloud security

Job description

Job Category

Enterprise Technology & Infrastructure



Job Details


About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.


Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.



The Experience

Salesforce is seeking a Lead Incident Responder for our GovCloud Computer Security Incident Response Team (CSIRT). The CSIRT provides 24x7x365 security monitoring and rapid incident response across all Salesforce environments. This role focuses on the US Federal Risk and Authorization Management Program (FedRAMP) environment, acting as the last line of defense protecting company and customer data from adversaries.


This position sits within the AMERS CSIRT, supporting the US GovCloud environment. On-call work, including evenings and weekends, is required as needed. Core hours are 10:30 AM - 6:30 PM EST, Monday through Friday.



What You'll Actually Be Doing


  • Manage the response to high-severity security incidents and act as a technical escalation point for the Incident Responder team.

  • Lead cross-functional response to high-priority, high-visibility security issues, including insider investigations, advanced adversaries, and web application attacks.

  • Drive process improvement and automation for detection and incident response capabilities.

  • Lead strategic projects that enhance detection and response capabilities within the environment.



You're Our Person If…


  • You have 8+ years of experience in information security, including operational security monitoring and incident response.

  • You have system forensics and investigation skills across Windows, Mac OS X, and Linux, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise.

  • You have strong technical understanding of the information security threat landscape, including attack vectors, tools, and best practices for securing systems and networks.

  • You communicate clearly and effectively with executive leadership, both verbally and in writing.



Even Better If…


  • You're a subject matter expert in a domain such as malware analysis, detection writing, forensics, cloud security, or offensive security.

  • You have experience responding to security incidents in cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud), including familiarity with relevant architectures, continuous integration/continuous delivery (CI/CD), and logging.

  • You have prior experience in a 24x7x365 operations environment.

  • You've driven automation and capability uplift through tool development, artificial intelligence, or security orchestration, automation, and response (SOAR) platforms.

  • You hold relevant information security certifications, such as SANS GCIH, SANS GPEN, SANS GFCA, or Offensive Security OSCP.



This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.



Unleash Your Potential

When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love.



Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.



Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates' resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.



Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that's inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.



In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program.



More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.



The typical base salary range for this position is $172,500 - $260,100 annually.



The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Incident Responder, CSIRT
Lead Incident Responder, CSIRT

salesforce.com, inc. • Washington

On-site
USD 173,000 - 260,000
Lead Incident Responder, CSIRT
Lead Incident Responder, CSIRT

100 Salesforce, Inc. • Virginia (MN)

Hybrid
USD 173,000 - 260,000
Time off programs
Medical
Dental
+6
Lead Incident Responder, CSIRT
Lead Incident Responder, CSIRT

Salesforce, Inc. • Washington

On-site
USD 173,000 - 260,000
Senior Lead Incident Responder
Senior Lead Incident Responder

Socket.dev • Seattle (WA)

On-site
USD 173,000 - 260,000
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Salesforce • Herndon (VA)

On-site
USD 111,000 - 122,000
Security GRC Senior Analyst
Security GRC Senior Analyst

Salesforce, Inc. • United States

On-site
USD 117,000 - 177,000
Security Problem Management Principal
Security Problem Management Principal

Salesforce • McLean (VA)

On-site
USD 197,000 - 314,000
Senior Lead Incident Responder
Senior Lead Incident Responder

Salesforce • Seattle (WA)

On-site
USD 173,000 - 260,000
Security Problem Management Principal
Security Problem Management Principal

Socket.dev • McLean (VA)

On-site
USD 197,000 - 314,000
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]

Salesforce, Inc. • Herndon (VA)

On-site
USD 111,000 - 122,000