To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & Infrastructure
Job Details
The Experience
Salesforce is seeking a Lead Incident Responder for our GovCloud Computer Security Incident Response Team (CSIRT). The CSIRT provides 24x7x365 security monitoring and rapid incident response across all Salesforce environments. This role focuses on the US Federal Risk and Authorization Management Program (FedRAMP) environment, acting as the last line of defense protecting company and customer data from adversaries.
This position sits within the AMERS CSIRT, supporting the US GovCloud environment. On-call work, including evenings and weekends, is required as needed. Core hours are 10:30 AM - 6:30 PM EST, Monday through Friday.
What You'll Actually Be Doing
- Manage the response to high-severity security incidents and act as a technical escalation point for the Incident Responder team.
- Lead cross-functional response to high-priority, high-visibility security issues, including insider investigations, advanced adversaries, and web application attacks.
- Drive process improvement and automation for detection and incident response capabilities.
- Lead strategic projects that enhance detection and response capabilities within the environment.
You're Our Person If...
- You have 8+ years of experience in information security, including operational security monitoring and incident response.
- You have system forensics and investigation skills across Windows, Mac OS X, and Linux, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise.
- You have strong technical understanding of the information security threat landscape, including attack vectors, tools, and best practices for securing systems and networks.
- You communicate clearly and effectively with executive leadership, both verbally and in writing.
Even Better If...
- You're a subject matter expert in a domain such as malware analysis, detection writing, forensics, cloud security, or offensive security.
- You have experience responding to security incidents in cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud), including familiarity with relevant architectures, continuous integration/continuous delivery (CI/CD), and logging.
- You have prior experience in a 24x7x365 operations environment.
- You've driven automation and capability uplift through tool development, artificial intelligence, or security orchestration, automation, and response (SOAR) platforms.
- You hold relevant information security certifications, such as SANS GCIH, SANS GPEN, SANS GFCA, or Offensive Security OSCP.
This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.
At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions.
The typical base salary range for this position is $172,500 - $260,100 annually.
The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.