Lead Incident Responder, CSIRT

2 weeks ago


Washington, United States Salesforce Full time

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Enterprise Technology & Infrastructure

Job Details About Salesforce We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place. Salesforce - the leader in enterprise cloud computing and one of the top 10 places to work according to Fortune magazine - is seeking a Lead Incident Responder for our Computer Security Incident Response team (CSIRT). The CSIRT is responsible for 24x7x365 security monitoring and rapid incident response across all Salesforce environments. We are the ‘tip of the spear’ and the last line of defense protecting company and customer data from our adversaries. The Lead Incident Responder will manage the response to high severity incidents, act as a technical escalation point for the team of Incident Responders, and develop process improvement and automation. This individual will also lead significant strategic projects, focused on enhancements to detection and incident response capabilities. This position is with the AMERS CSIRT, a part of the Global CSIRT. As a result, on-call work (including overnight and weekends) is required on an as needed basis. The core hours for this position are 10:30AM EST - 6:30PM EST, Monday through Friday. Some positions are during this time and others will be a 4X10 working Sunday to Wednesday, or Wednesday to Saturday from 10AM EST - 8PM EST.

Required Skills: 8+ years experience in the Information Security field, including operational security monitoring and incident response experience.

System

forensics/investigation

skills across Windows, Mac OS X, Linux, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of

infection/compromise.

Familiarity responding to security incidents in various cloud environments (AWS, Azure, Google Cloud) with knowledge of relevant architectures, CI/CD, and logging.

The ability to cross-functionally lead and manage the response to high priority, high visibility operational security issues including insider investigations, advanced adversaries, and web application attacks.

The ability to build strong relationships with peers both internal and external to your functional group, and with peers/professional organizations outside your company.

Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.).

Must have strong verbal and written communication skills; ability to communicate effectively and clearly to executive leadership.

U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship. Agree to complete a Minimum Background Investigation (MBI) for a Moderate Public Trust position with the U.S. federal government.

Desired Skills: Subject matter expert in a domain (e.g. malware analysis, detection writing, forensics, cloud security, offensive security)

Prior experience in a 24x7x365 operations environment.

Demonstrated history of automation and capability uplift through tool development, SOAR, etc.

Relevant information security certifications, such as SANS GCIH, SANS GPEN, SANS GFCA, Offensive Security OSCP, etc.

Accommodations If you require assistance due to a disability applying for open positions please submit a request via this

Accommodations Request Form . Posting Statement At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at

www.equality.com

and explore our company benefits at

www.salesforcebenefits.com

. Salesforce

is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Salesforce

does not accept unsolicited headhunter and agency resumes.

Salesforce

will not pay any third-party agency or company that does not have a signed agreement with

Salesforce

. Salesforce welcomes all.

#J-18808-Ljbffr



  • Washington, United States JetBlue Airways Full time

    Position Title: Senior Incident Responder – Cyber Security Position Summary At JetBlue, cybersecurity operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, and a diverse end-user environment. We are committed to providing robust security for our extensive...


  • Washington, United States DAn Solutions Inc Full time

    REQUIRES AN ACTIVE/EXISTING TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK, MUST WORK ON SITE Job Description Summary Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction. Monitor, evaluate, and maintain systems and procedures to safeguard internal...


  • Washington, United States MissionSquare Retirement Full time

    Join a great place to work with MissionSquare Retirement, a FINANCIAL SERVICES LEADER in public sector employee retirement products and services. Headquartered in Washington, DC, MissionSquare Retirement was founded to provide portable retirement benefits for city and county managers, enabling accumulated retirement assets to be transferred between...


  • Washington, United States DAn Solutions, Inc Full time

    REQUIRES AN ACTIVE/EXISTING TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK, MUST WORK ON SITEJob Description SummaryPerforms all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction. Monitor, evaluate, and maintain systems and procedures to safeguard internal...

  • CSIRT Analyst

    1 week ago


    Washington, United States Hamilton Barnes Associates Limited Full time

    Hamilton Barnes is representing a European transformational consultancy with over 3000 employees and 20 office locations. with a mission to shape the future of cybersecurity. This 12-month contract offers the potential for an extension over 3 years, with onsite work in Hasselt 1-2 days per week. This role is integral to meeting the increased demand for SOC...


  • Washington, United States ShorePoint Full time

    Job DescriptionJob DescriptionSalary: Who we are: ShorePoint is a fast-growing, industry recognized, and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard”...


  • Washington, United States Leidos Full time

    **Description** The OIM is responsible to meet the following performance requirements: - Infrastructure Operations: The OIM will work to optimize and minimize the cost of infrastructure operations and identify and implement opportunities for improvement. The OIM will work with OCIO management to define infrastructure support initiatives and solutions for...

  • Incident Manager

    4 weeks ago


    Washington, United States TikTok Full time

    Responsibilities TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and its offices include New York, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo. Why Join Us Creation is the core of TikTok's purpose....

  • Incident Manager

    2 weeks ago


    Washington, United States JCD Staffing Full time

    We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and Communications Management, and After-Action Root...


  • Washington, United States Edgewater Federal Solutions Full time

    Overview Edgewater Federal Solutions is currently seeking a Mid-Level Incident Response Analyst to provide advanced Incident Response expertise and support to maximize cyber fusion throughout the Client's SOC, ensuring the Client's infrastructure and operations remain safe and secure from the full spectrum of cyber threats. The Mid-Level Incident Response...


  • Washington, United States Base-2 Solutions, LLC Full time

    Job Description Perform all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction. Monitor, evaluate, and maintain systems and procedures to safeguard internal information systems, network, databases, and Web-based security. Monitors and analyzes Intrusion...


  • Washington, United States Charles River Associates Full time

    **About Charles River Associates** CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services -...


  • Washington, United States The Carlyle Group Full time

    **Basic information**: - Job Name: - Administrator, Incident Response- Location: - Washington, DC- Line of Business: - Global Technology & Solutions- Job Function: - Investor Services- Date: - Thursday, April 25, 2024**Position Summary**: - The Incident Response Analyst role plays a critical role in safeguarding sensitive financial data and systems from...


  • Washington, United States JCD STAFFING LLC Full time

    Job Description Job Description Job Description: We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and...


  • Washington, United States JCD STAFFING LLC Full time

    Job Description Job Description Job Description:We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and...


  • Washington, United States JCD STAFFING LLC Full time

    Job DescriptionJob DescriptionJob Description:We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and...


  • Washington, United States JCD STAFFING LLC Full time

    Job DescriptionJob DescriptionJob Description:We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and...


  • Washington, United States Network Designs Full time

    Job Description: We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and Communications Management, and...


  • Washington, United States Network Designs Full time

    Job Description: We are seeking a highly skilled and experienced Incident and Release Manager, who will be responsible for the Incident, Problem, and Release processes within the program. For Incident and Problem Management this would include Incident Triage methodologies, Impact Assessments, Troubleshooting, Stakeholder and Communications Management, and...


  • Washington, United States Highlighttech Full time

    Overview Highlight is looking for an Incident Response Manager to play a crucial role in managing incidents, ensuring smooth operations, and continuously improve the incident management process to meet customer expectations and maintain a high level of service quality in a 24/7/365 environment. Responsibilities Provide Incident Management services to meet...