Senior Incident Responder, Global CSIRT

SalesforceMclean, VA
Remote

About The Position

Salesforce's Computer Security Incident Response Team (CSIRT) provides 24x7x365 security monitoring and rapid incident response across every Salesforce environment, protecting company and customer data from adversaries. As a Senior Incident Responder, you'll be a core member of the response team — investigating and handling security incidents end to end, taking a lead role on many of them, and escalating to Lead Incident Responders on the most severe or ambiguous events. You'll also help improve the playbooks, detections, and automation that make the team faster, and mentor newer analysts as you grow toward a lead role yourself. This is a hands-on technical role focused on the detailed work of incident response.

Requirements

  • 5+ years in information security, including hands-on operational security monitoring and incident response.
  • Ability to perform host and network forensics across Windows, macOS, and Linux — analyzing file system, memory, process, and network artifacts for indicators of compromise.
  • Experience responding to incidents in cloud environments (AWS, Azure, and/or GCP), including familiarity with cloud architectures, CI/CD (continuous integration/continuous delivery) pipelines, and cloud logging/telemetry.
  • Experience handling high-priority incidents, including insider investigations, adversary activity, and web application attacks.
  • Solid, current understanding of the threat landscape — attacker tactics, techniques, and procedures (TTPs), tooling, and hardening best practices — including working knowledge of a framework such as MITRE ATT&CK.
  • Clear written and verbal communication skills, ability to document incidents effectively, and build trusted relationships with peers inside and outside your team.
  • Must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Nice To Haves

  • Developing depth in a specialty — malware analysis, detection engineering, forensics, cloud security, offensive security, or applied AI/ML for security.
  • Prior experience in a 24x7x365 security operations environment.
  • Experience improving team capability through automation and tool development.
  • Relevant certifications: SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or Offensive Security OSCP.
  • Experience applying AI and LLMs to SOC operations — AI-powered tooling, LLM-assisted threat analysis, and AI-driven detection.
  • Strong understanding of the Salesforce platform and its SaaS offerings.

Responsibilities

  • Investigate and respond to security incidents end to end — triage, containment, eradication, recovery, and post-incident review — taking point on many incidents and supporting Lead Incident Responders on the highest-severity, highest-visibility events.
  • Investigate adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments.
  • Contribute to process improvements, playbooks, and automation — including Security Orchestration, Automation, and Response (SOAR) tooling and detection-as-code — that reduce time-to-detect and time-to-respond, and support strategic projects expanding detection and response capabilities.
  • Produce clear incident documentation and status updates for technical and non-technical stakeholders, mentor newer incident responders, and support the team's on-call rotation (core hours 10:30 AM–6:30 PM ET, Monday–Friday, with occasional overnight/weekend on-call as needed).

Benefits

  • time off programs
  • medical
  • dental
  • vision
  • mental health support
  • paid parental leave
  • life and disability insurance
  • 401(k)
  • employee stock purchasing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service