Lead Vulnerability Commander

SalesforceWashington DC, VA
Onsite

About The Position

As a Lead Vulnerability Commander on the Vulnerability Management team, you own the response to the most critical vulnerabilities end to end. As commanders on the most impactful cyber security team, we lead Salesforce’s security response for our Commercial and GovCloud environments while acting as the security executive liaison with Security and Business Leadership across the lifecycle of events. Frontier AI models have drastically decreased the time to exploit vulnerabilities and these need an incident-level response. You are that person and this is a driving role, not a passive coordination seat. You engage the owning engineering team, brief them on the fix and the remediation expectation, track the SLA, escalate to leadership when the clock is at risk, and run retros that feed process and tooling improvements back to Engineering partners. This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role.

Requirements

  • 8+ years in vulnerability management, incident response, security operations, or a closely related field.
  • A track record of coordinating cross-team remediation under tight deadlines.
  • Strong grasp of vulnerability severity, exploitability, and how critical findings are triaged and fixed.
  • Experience working directly with engineering teams to drive fixes to completion.
  • Ability to hold senior engineers and stakeholders to a shared deadline without formal authority over them.
  • Comfort escalating to leadership with a clear, factual read of risk and status.
  • Excellent written and verbal communication skills.
  • Familiarity with SLA tracking, metrics, and retro-driven process improvement.
  • Experience using or building AI-driven tooling for security triage, investigation, or decision support.
  • This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role, including a Criminal Justice Information Services screening with fingerprint scan.
  • Due to the citizenship requirements for this role, which supports U.S. federal, state, and/or local government customers, citizenship will be verified through two of the following REAL ID Act documents: U.S. Passport, Passport Card, REAL Driver’s License, Global Entry Card, U.S. Government CAC/PIV.
  • You agree to complete a Minimum Background Investigation (MBI) for a Moderate Public Trust position with the U.S. federal government and gain other clearances as deemed appropriate for the role.
  • This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Nice To Haves

  • Technical knowledge of complex systems and Cloud environments (AWS, GCP, Azure).
  • Technical knowledge of network fundamentals and common Internet protocols.
  • Technical knowledge of incident response frameworks with operational experience across Windows, Mac and Linux forensics

Responsibilities

  • Owning the critical vulnerability response end to end: engaging the owning engineering team, coordinating the fix, and driving the fix to closure.
  • Briefing engineering owners on the required fix and the 24-hour expectation alongside Security stakeholders.
  • Tracking each case against its SLA and escalating to leadership the moment a deadline is at risk, translating technical status into a clear read of risk, impact, and the decisions needed.
  • Running a retrospective after each response to identify systemic causes and drive concrete prevention, not just closing the individual case.
  • Taking those findings back to stakeholders to improve process and tooling.
  • Partnering with the Threat Intelligence and Product Security teams to make the final call on if a vulnerability meets the criteria.
  • Reporting volume, response times, and SLA adherence to Security and Engineering leadership.
  • Running tabletop exercises and readiness drills so teams can meet the clock before a real critical finding lands.
  • Building playbooks, tracking, and agentic automation that enables this process to not become the bottleneck.

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • an employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service