About The Position

Salesforce is seeking an Incident Response Analyst for its Government Cloud Security Operations team, specifically within the Salesforce National Security (SNS) Infrastructure Security Team. This team is on the front lines, protecting critical infrastructure and customer data from advanced information security threats within environments supporting US Government agencies. The role involves 24x7x365 security monitoring, real-time analysis of security alerts, and rapid incident response across SNS Cloud environments. The position is customer-facing and requires the analyst to be on-site in Northern Virginia. It offers exposure to various security disciplines including incident response, forensics, reverse engineering, malware analysis, intrusion detection, network security, and system security. Opportunities exist to automate workflows, develop new analytics, apply mitigations for adversary Tactics, Techniques, and Procedures (TTPs), and hunt for indicators of compromise. The role may require 24x7 on-call support and occasional local travel to customer sites.

Requirements

  • Must be a U.S. citizen.
  • Must have an active U.S. Government Top Secret/SCI security clearance with Polygraph.
  • A related technical degree, such as Computer Science, Software Engineering, Cybersecurity, Information Assurance, or equivalent work experience.
  • 2+ years of experience in cybersecurity, engineering, and/or incident response roles.
  • Strong interpersonal and communication skills for coordinating responses across the organization with non-technical and technical stakeholders.
  • Strong problem-solving ability.
  • Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.).
  • Must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship.
  • Agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Nice To Haves

  • Experience with AWS Cloud, Splunk, Azure Sentinel, or ElasticStack.
  • Technical understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.).
  • Familiarity with incident response and security operations within cloud environments.
  • Familiarity with Mac OSX, Microsoft Windows, and Linux/Unix system administration and security controls.
  • Technical understanding of AWS, Azure, or GCP administration and security controls.
  • Experience creating and managing event and metric dashboards with tools like Splunk, Kibana, Grafana, etc.
  • Experience with data query languages, such as SQL, SPL, GraphQL, etc.
  • Scripting language (i.e. Bash, Python, etc.) and workflow automation experience.
  • Operational experience monitoring devices such as network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools, and operating system logs.
  • System forensics/investigation skills, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise.
  • Relevant information security certifications, such as CISSP, GCFR, GCIA, GCIH or other related certifications.

Responsibilities

  • Respond to and investigate cyber security events within SNS Cloud environments.
  • Track and document security events and incidents in a ticketing system.
  • Analyze log data for signs of malicious activity using a Security Information and Event Manager (SIEM).
  • Coordinate incident response actions across multi-disciplined teams for high-priority, high-transparency operations security issues.
  • Drive incident response to resolution while meeting required service-level agreements.
  • Escalate issues as appropriate.
  • Provide regular updates to senior leaders.
  • Automate workflows and processes.
  • Develop new analytics.
  • Apply mitigations for adversary Tactics, Techniques, and Procedures (TTPs).
  • Hunt for undetected indicators of compromise.
  • Provide periods of 24x7 on-call support on an as-needed basis.
  • Provide occasional local travel to customer sites.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service