Hiring.Camp

Lead, Incident Response – Global CSIRT

Salesforce

·

Yesterday

Salary
$173k – $260k
Location
Virginia - Mclean, United States of America · Washington - Bellevue
Workplace
Onsite
Type
Full-time
Seniority
Lead
Visa
Not sponsored
Source
Workday

Description

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Enterprise Technology & Infrastructure

Job Details

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience

Salesforce's Computer Security Incident Response Team (CSIRT) provides 24x7x365 security monitoring and rapid incident response across every Salesforce environment. We are the last line of defense protecting company and customer data from our adversaries.

As Lead Incident Responder, you will own the response to our highest-severity incidents, serve as the senior technical escalation point for the incident response team, and drive the process improvements and automation that make the whole team faster. You'll also lead strategic initiatives that raise our detection and response capabilities across the board, and mentor the responders who will grow into these roles behind you.

This is a hands-on senior technical role, not a people-management position, though it carries significant influence over how the team operates.

Core hours are 10:30 AM – 6:30 PM ET, Monday through Friday. Because CSIRT operates 24x7x365, on-call rotation, including occasional overnights and weekends, is required on an as-needed basis.

What You'll Actually Be Doing
 
  • Lead end-to-end response to high-severity, high-visibility incidents, from initial triage through containment, eradication, recovery, and post-incident review.
  • Act as the technical escalation point and on-shift decision-maker for the incident response team.
  • Investigate sophisticated adversaries, insider threats, and web application attacks across on-premises and multi-cloud environments.
  • Design and build process improvements, playbooks, and automation, including security orchestration, automation, and response (SOAR) tooling and detection-as-code, that reduce time-to-detect and time-to-respond.


You're Our Person If...
 
  • You have 8+ years in information security, with substantial hands-on operational security monitoring and incident response experience.
  • You've done host and network forensics across Windows, macOS, and Linux, analyzing file system, memory, process, and network artifacts for indicators of compromise.
  • You have experience responding to incidents in cloud environments (AWS, Azure, and/or GCP), including familiarity with cloud architectures, CI/CD (continuous integration/continuous delivery) pipelines, and cloud logging/telemetry.
  • You have a deep, current understanding of the threat landscape, including attacker tactics, techniques, and procedures (TTPs), and system/network hardening best practices, ideally with working knowledge of a framework such as MITRE ATT&CK.


Even Better If...
 
  • You have recognized depth in a specialty: malware analysis, detection engineering, forensics, cloud security, offensive security, or applied AI/ML for security.
  • You have prior experience in a 24x7x365 security operations environment.
  • You have a track record of capability uplift through automation and tool development (SOAR, scripting, detection-as-code).
  • You hold relevant certifications, such as SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or Offensive Security OSCP.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Unleash Your Potential

When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $172,500 - $260,100 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Skills

AWSAzureGCPCI/CDLinuxSalesforce

Similar Jobs

28

Incident Response Lead

Leidos · 9356 Washington DC Non-specific Customer Site, United States of America +1

1 week ago

Incident Response Lead

B&H Photo · 440 9th Ave, New York, NY 10001, USA

2 weeks ago

Incident response Lead

Ringcentral · Spain Valencia

3 weeks ago

Incident Response Lead

Whoop · Boston, MA · Onsite

1 month ago

Incident Response Lead

Adobe · Bucharest, Romania

3 months ago

Incident Response Lead

Whoop · Boston, MA · Onsite

5 months ago

Cyber Defense Incident Response Lead

Keybank · 4910 Tiedeman Road, Brooklyn, OH, United States of America +1 · Remote

2 days ago

Production Support & Incident Response Lead

Evismart · BGC, Taguig, Philippines +1 · Onsite

3 days ago

CSOC Incident Response Lead

Sherwin-Williams · Cleveland, OH, United States, US

1 week ago

Incident Response Lead/Advisor

Anavationllc · Reston, VA · Onsite

1 week ago

Engagement Lead, Incident Response

Areteir · United States, United States of America

2 weeks ago

Tier 3 Incident Response Lead

Tyto Athene · Washington, DC, US · Hybrid

1 month ago

Cybersecurity Incident Response Lead

Caa · London, United Kingdom

4 months ago

IT Security Specialist (Pre-Incident Consulting & Incident Response Lead)

Mirazon · Louisville, Kentucky

6 months ago

Tech Lead Incident Response (CERT/CSIRT) (F/H)

Michelinhr · Clermont-Ferrand, France · Hybrid

7 months ago

Senior Information Security Incident Response Lead

Nttlimited · Jakarta, Indonesia · Onsite

1+ year ago

Cybersecurity Program Manager (PgM) & Incident Response (IR) Lead

ShorePoint · Albuquerque, New Mexico

1 month ago

Security Incident Response Orchestration Lead

Ghr · Chicago, United States of America +2 · Onsite

1 month ago

Security Incident Response Orchestration Lead

Ghr · Chicago, United States of America +2 · Onsite

1 month ago

Technology Support Lead - Incident Management & Response (IMR)

JPMorgan Chase · Seattle, WA, United States, US

2 months ago

Technology Support Lead - Incident Management & Response (IMR)

JP Morgan Chase · Seattle, WA, United States, US

2 months ago

Incident Response Team Lead

Agile Defense · Reston, VA · Hybrid

6 months ago

Senior/Lead Cyber Security - Incident Response Engineer

Fico · Work from Home, United States, United States of America · Remote

3 weeks ago

Incident Response and Forensics Lead

Accenturefederalservices · Germantown, MD; Washington, DC +1 · Onsite

1 month ago

SOC Technical Lead – Threat Hunting & Incident Response

Thales · Madrid Emilio Vargas, Spain · Hybrid

1 month ago

Lead Consultant - FortiGuard Incident Response - Kuwait

Fortinet · Kuwait City, Kuwait, KW · Hybrid

3 months ago

Lead, Digital Forensics & Incident Response Investigator

Globe · NCR - WGC, Philippines

4 months ago

Incident Response (IR) and Forensics Lead (Q Clearance)

ShorePoint · Germantown, Maryland

3 weeks ago