Lead, Incident Response – Global CSIRT

Salesforce
Bellevue
Workplace: OnsiteFull timeUSD 172,500 - 260,100 annuallyFunction: Administration & Executive AssistanceExperience: 8+ yearsSkills: ["Mentorship","Process improvement","Decision-making"]

Own end-to-end response for Salesforce’s highest-severity incidents as the senior technical escalation point for the CSIRT team. Lead hands-on investigations across on-prem and multi-cloud environments, including sophisticated adversaries and web application attacks. Improve detection and response through automation, playbooks, and SOAR tooling/detection-as-code, and raise overall capabilities while mentoring responders. Participate in an on-call rotation supporting 24x7x365 operations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
3 days ago

Lead, Incident Response – Global CSIRT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Own end-to-end response for Salesforce’s highest-severity incidents as the senior technical escalation point for the CSIRT team. Lead hands-on investigations across on-prem and multi-cloud environments, including sophisticated adversaries and web application attacks. Improve detection and response through automation, playbooks, and SOAR tooling/detection-as-code, and raise overall capabilities while mentoring responders. Participate in an on-call rotation supporting 24x7x365 operations.
Location: Bellevue
Workplace: Onsite
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Lead end-to-end response to high-severity incidents from triage through containment, eradication, recovery, and post-incident review.
  • •Serve as the technical escalation point and on-shift decision-maker for the incident response team.
  • •Investigate advanced adversaries, insider threats, and web application attacks across on-premises and multi-cloud environments.
  • •Design and build incident response process improvements, playbooks, and automation, including SOAR tooling and detection-as-code.
  • •Lead strategic initiatives to raise detection and response capabilities and mentor responders.

Pay and Benefits

Salary: USD 172,500 - 260,100 annually
Perks:Health InsuranceDentalVisionPaid ParentalLife InsuranceDisability Insurance401kEquity

Key Requirements

  • •8+ years in information security with substantial hands-on incident response and security monitoring experience.
  • •Experience with host and network forensics across Windows, macOS, and Linux.
  • •Incident response experience in cloud environments (AWS, Azure and/or GCP), including familiarity with cloud architectures, CI/CD, and logging/telemetry.
  • •Strong understanding of the threat landscape (TTPs) and system/network hardening, ideally with MITRE ATT&CK.
  • •Relevant certifications such as SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or Offensive Security OSCP.
Experience:8+ yearsIncident responseSecurity operationsCloud securityThreat detectionForensics
Skills:MentorshipProcess improvementDecision-making
Certifications:SANS GCIHGCFAGCFEGNFAGPENGREMOffensive Security OSCP
Tech Stack:SOARDetection-as-codeCI/CDMITRE ATT&CKAWSAzureGCPWindowsMacOSLinuxSecurity orchestrationSecurity monitoringWeb application attacks

Eligibility

Nationality:US National
Security Clearance:Moderate Public Trust

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor