Senior Incident Responder, CSIRT

Salesforce
Dublin
Workplace: OnsiteFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 5+ yearsSkills: ["Creative problem-solving","Communication","Relationship building","Customer-centricity","Integrity"]

Work on Salesforce’s 24x7x365 Cyber Security Incident Response Team (CSIRT), investigating and responding to security incidents across all Salesforce environments. Conduct threat hunts, enhance detection and incident response capabilities, and improve CSIRT technologies and processes. The role requires on-call participation via a rotating schedule and supports a “follow the sun” operating model for EMEA, protecting company and customer data from advanced threats.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
1 day ago

Senior Incident Responder, CSIRT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Work on Salesforce’s 24x7x365 Cyber Security Incident Response Team (CSIRT), investigating and responding to security incidents across all Salesforce environments. Conduct threat hunts, enhance detection and incident response capabilities, and improve CSIRT technologies and processes. The role requires on-call participation via a rotating schedule and supports a “follow the sun” operating model for EMEA, protecting company and customer data from advanced threats.
Location: Dublin
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Participate in technical investigations during security incidents to protect critical infrastructure and customer data.
  • •Conduct threat hunts and contribute to strategic CSIRT projects to improve detection and incident response capabilities.
  • •Enhance core CSIRT technologies and processes for security monitoring and rapid incident response.
  • •Perform incident response activities including containment and remediation in response to large-scale network compromises.
  • •Participate in on-call rotation as part of the team’s 24x7x365 operating model.

Key Requirements

  • •Minimum 5+ years of specialized security operations experience, including technical investigations, containment, and remediation in a production environment.
  • •Operational experience responding to cybersecurity incidents on large-scale network compromises.
  • •Operational experience with Endpoint Detection and Response (EDR) solutions (e.g., CrowdStrike, Cybereason).
  • •Operational experience with SIEM/incident and event management solutions (e.g., Splunk, Google Security Operations, Microsoft Sentinel).
  • •Experience with security monitoring tools/devices and familiarity with security incident response fundamentals and the security threat landscape.
Experience:5+ years
Skills:Creative problem-solvingCommunicationRelationship buildingCustomer-centricityIntegrity
Certifications:OSCPSANS GCIHGCIAGCFAGCFEGX-IHGX-FA
Tech Stack:EDRCrowdStrikeCybereasonSIEMSplunkGoogle Security OperationsMicrosoft SentinelSecurity Service EdgeIntrusion detection systemsWeb application firewallsDatabase security monitoringFirewallsRoutersSwitchesProxy serversAntivirusFile integrity monitoringPythonBashGo

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor