Senior Incident Responder, Global CSIRT

Salesforce
Bellevue
Workplace: OnsiteFull timeUSD 148,500 - 223,900 annuallyFunction: Solutions Engineering & Sales EngineeringExperience: 5+ yearsSkills: ["Communication","Documentation","Mentoring","Stakeholder management","Problem-solving"]

Join Salesforce’s Computer Security Incident Response Team (CSIRT) to investigate and respond to security incidents end to end—triaging, containing, eradicating, and recovering while leading many investigations. You’ll analyze adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments, improve SOAR and detection-as-code capabilities, and produce clear incident documentation and stakeholder updates while supporting the team’s on-call rotation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
3 days ago

Senior Incident Responder, Global CSIRT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Join Salesforce’s Computer Security Incident Response Team (CSIRT) to investigate and respond to security incidents end to end—triaging, containing, eradicating, and recovering while leading many investigations. You’ll analyze adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments, improve SOAR and detection-as-code capabilities, and produce clear incident documentation and stakeholder updates while supporting the team’s on-call rotation.
Location: Bellevue
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Investigate and respond to security incidents end to end, taking point on many incidents and supporting Lead Incident Responders on the highest-severity events.
  • •Investigate adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments.
  • •Improve playbooks and automation, including SOAR tooling and detection-as-code, to reduce time-to-detect and time-to-respond.
  • •Produce clear incident documentation and status updates for technical and non-technical stakeholders.
  • •Mentor newer incident responders and support the team’s on-call rotation (core hours 10:30 AM–6:30 PM ET, Monday–Friday, with occasional overnight/weekend on-call as needed).

Pay and Benefits

Salary: USD 148,500 - 223,900 annually
Perks:MedicalDentalVision401kPaid ParentalLife InsuranceDisability InsuranceHealth Insurance

Key Requirements

  • •5+ years in information security with hands-on operational security monitoring and incident response experience.
  • •Perform host and network forensics across Windows, macOS, and Linux, and respond to incidents in cloud environments (AWS, Azure, and/or GCP).
  • •Handle high-priority incidents, including insider investigations, adversary activity, and web application attacks, with knowledge of the threat landscape and attacker TTPs.
  • •Use and understand a framework such as MITRE ATT&CK and hardening best practices.
  • •Communicate clearly in writing and verbally and document incidents effectively while building trusted relationships.
Experience:5+ yearsInformation securityIncident response24x7 security operationsSOC operations
Skills:CommunicationDocumentationMentoringStakeholder managementProblem-solving
Certifications:SANS GCIHGCFAGCFEGNFAGPENGREMOffensive Security OSCP
Tech Stack:Information securityIncident responseHost and network forensicsWindowsMacOSLinuxAWSAzureGCPCloud loggingTelemetryCI/CDSOARDetection-as-codeMITRE ATT&CKAILLMsAI-powered toolingThreat analysisWeb application attacks

Eligibility

Nationality:US National
Security Clearance:Moderate Public Trust

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor