Incident Responder

Salesforce•Mclean, VA
•Onsite

About The Position

Salesforce is seeking an Incident Responder to join our Computer Security Incident Response Team (CSIRT). The CSIRT provides around-the-clock security monitoring and rapid incident response across all Salesforce environments, acting as the last line of defense protecting company and customer data from security threats. As a key member of the Global CSIRT, you'll help protect Salesforce's critical infrastructure and customer data from evolving threats. This role operates from our 24x7 operations center and requires shift work, including on-call shifts and weekends.

Requirements

  • 2+ years of experience in an IT operations environment, or 1+ years of specialized security operations experience.
  • Foundational knowledge of information security, including current threats, best practices, network fundamentals, and common internet protocols (DNS, HTTP, HTTPS/TLS, SMTP).
  • Understand operating system administration and security controls for macOS, Microsoft Windows, and Linux/Unix, along with core concepts of incident response (phases of response, vulnerabilities vs. threats vs. actors, and Indicators of Compromise).
  • Able to build strong working relationships across internal and external teams.
  • Hold U.S. citizenship (born or naturalized, no dual citizenship) with the ability to pass a Minimum Background Investigation for a Moderate Public Trust position with the U.S. federal government.

Nice To Haves

  • Hands-on experience with security infrastructure such as intrusion detection/response tools, WAFs, firewalls, proxies, antivirus, file integrity monitoring, and OS logs.
  • In-depth understanding of the information security threat landscape, including attack vectors, tools, and best practices.
  • Contributed to cross-functional, global security projects and enjoy continuously learning new skills and processes.
  • Hold relevant certifications (e.g., CompTIA Security+, BTL1, SANS GCFA, GCIH) or have a degree in Computer Science, Cybersecurity, or a related field, plus foundational understanding of GenAI, Agentic AI, and prompt engineering.

Responsibilities

  • Perform CSIRT's Tier 1 monitoring function around the clock, triaging and prioritizing security alerts to identify threats requiring escalation.
  • Support containment, eradication, and recovery efforts during security incidents, following established playbooks and guidance from senior team members.
  • Collaborate with engineering, business, and security teams to coordinate response efforts and drive organizational security improvements.
  • Document findings clearly and keep stakeholders informed with accurate incident notes and summaries throughout the response process.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service