Associate Incident Responder - CSIRT

Salesforce
Sydney
Workplace: OnsiteFull timeFunction: Product ManagementSkills: ["Flexibility","Drive","Integrity","Creative problem-solving","Communication","Relationship building"]

Join Salesforce’s Cyber Security Incident Response Team (CSIRT) as an Associate Incident Responder and help protect company and customer data through 24x7x365 monitoring and rapid incident response. You’ll contribute to CSIRT projects, run threat hunts, and improve core workflows while supporting security operations across endpoints, logs, networks, and cloud environments. Work follows a follow-the-sun shift model, collaborating with internal and external peers.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
2 days ago

Associate Incident Responder - CSIRT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 22 hours agoStatus: Live

Job Summary

Join Salesforce’s Cyber Security Incident Response Team (CSIRT) as an Associate Incident Responder and help protect company and customer data through 24x7x365 monitoring and rapid incident response. You’ll contribute to CSIRT projects, run threat hunts, and improve core workflows while supporting security operations across endpoints, logs, networks, and cloud environments. Work follows a follow-the-sun shift model, collaborating with internal and external peers.
Location: Sydney
Workplace: Onsite
Employment Type: Full time
Job Function: Product Management
Seniority: Mid level

Key Responsibilities

  • •Serve as a key member of the global CSIRT on the front lines of the Salesforce production environment.
  • •Contribute to CSIRT projects, including improving core CSIRT workflows and processes.
  • •Conduct threat hunts to identify and investigate potential security incidents.
  • •Support 24x7x365 security monitoring and rapid incident response across Salesforce environments.
  • •Collaborate with peers internally and externally, communicating clearly to technical and non-technical audiences.

Key Requirements

  • •Minimum 1 year of specialized security operations experience, with flexibility, drive, integrity, and creative problem-solving skills.
  • •Operational experience with Endpoint Detection and Response (EDR) tools (e.g., CrowdStrike).
  • •Operational experience with log analysis platforms (e.g., Splunk, Google Security Operations, Kibana).
  • •Working knowledge of security incident response concepts (response phases, vulnerabilities vs threats vs actors, and Indicators of Compromise).
  • •Understanding of network fundamentals and core protocols (DNS, HTTP, HTTPS/TLS, SMTP) and fundamentals of cloud security with public cloud experience (AWS, Azure, or GCP).
Experience:Security operations
Skills:FlexibilityDriveIntegrityCreative problem-solvingCommunicationRelationship building
Certifications:BTL1SAL1SANS GCIHGCFAGCFEGX-IHGX-FA
Tech Stack:CrowdStrikeSplunkGoogle Security OperationsKibanaAWSAzureGCPMac OSXMicrosoft WindowsLinuxUnixDNSHTTPHTTPSTLSSMTPPythonBashGoPowerShell

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor