Incident Responder
McLean, VA, USA · Bellevue, WA, USA
Posted on Oct 8, 2026
Job Description:
The Experience
Salesforce is seeking an Incident Responder to join our Computer Security Incident Response Team (CSIRT). The CSIRT provides around-the-clock security monitoring and rapid incident response across all Salesforce environments, acting as the last line of defense protecting company and customer data from security threats. As a key member of the Global CSIRT, you'll help protect Salesforce's critical infrastructure and customer data from evolving threats. This role operates from our 24x7 operations center and requires shift work, including on-call shifts and weekends.
What You'll Actually Be Doing
- Perform CSIRT's Tier 1 monitoring function around the clock, triaging and prioritizing security alerts to identify threats requiring escalation.
- Support containment, eradication, and recovery efforts during security incidents, following established playbooks and guidance from senior team members.
- Collaborate with engineering, business, and security teams to coordinate response efforts and drive organizational security improvements.
- Document findings clearly and keep stakeholders informed with accurate incident notes and summaries throughout the response process.
You're Our Person If...
- You have 2+ years of experience in an IT operations environment, or 1+ years of specialized security operations experience.
- You have foundational knowledge of information security, including current threats, best practices, network fundamentals, and common internet protocols (DNS, HTTP, HTTPS/TLS, SMTP).
- You understand operating system administration and security controls for macOS, Microsoft Windows, and Linux/Unix, along with core concepts of incident response (phases of response, vulnerabilities vs. threats vs. actors, and Indicators of Compromise).
- You're able to build strong working relationships across internal and external teams, and hold U.S. citizenship (born or naturalized, no dual citizenship) with the ability to pass a Minimum Background Investigation for a Moderate Public Trust position with the U.S. federal government.
Even Better If...
- You have hands-on experience with security infrastructure such as intrusion detection/response tools, WAFs, firewalls, proxies, antivirus, file integrity monitoring, and OS logs.
- You have an in-depth understanding of the information security threat landscape, including attack vectors, tools, and best practices.
- You've contributed to cross-functional, global security projects and enjoy continuously learning new skills and processes.
- You hold relevant certifications (e.g., CompTIA Security+, BTL1, SANS GCFA, GCIH) or have a degree in Computer Science, Cybersecurity, or a related field, plus foundational understanding of GenAI, Agentic AI, and prompt engineering.