Incident Responder

Salesforce

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
McLean, VABellevue, WA
Salary
$96,300–$145,200 / yr
Employment
Full-time
Posted
18 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $172k
This role $121k
$82k $230k
below market most similar roles pay here above market

This role pays less than 79% of similar roles. Most pay $127,875–$215,250 — the blue band above. At the midpoint, this role pays about $121k versus about $172k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 178 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 104 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Incident Responder

The Incident Responder joins the Computer Security Incident Response Team to provide around-the-clock security monitoring and rapid response across all Salesforce environments. As a key member of the Global CSIRT, you will perform Tier 1 monitoring, triaging and prioritizing security alerts to identify threats. You will support containment, eradication, and recovery efforts by following established playbooks and collaborating with engineering and security teams. The role requires foundational knowledge of network fundamentals, common internet protocols like DNS and HTTP, and operating system administration for macOS, Windows, and Linux/Unix. You must understand incident response phases, vulnerabilities, and indicators of compromise. Experience with intrusion detection tools, WAFs, firewalls, and proxies is preferred. This role protects critical infrastructure and customer data from evolving security threats in a 24x7 operations center.

What you'll do

  • Perform Tier 1 security monitoring around the clock to identify and triage security alerts.
  • Prioritize security threats and escalate high-priority incidents to the appropriate teams.
  • Support containment, eradication, and recovery efforts during active security incidents.
  • Follow established playbooks and guidance from senior team members during incident response.
  • Coordinate response efforts with engineering, business, and security teams to improve organizational security.
  • Document clear incident notes and summaries to keep stakeholders informed throughout the response process.

What we're looking for

  • You must have 2+ years of experience in an IT operations environment or 1+ years of specialized security operations experience.
  • You must have foundational knowledge of information security, network fundamentals, and common internet protocols like DNS, HTTP, and TLS.
  • You must understand operating system administration and security controls for macOS, Windows, and Linux/Unix.
  • You must understand core incident response concepts, including vulnerabilities, threats, actors, and Indicators of Compromise.
  • You must be a U.S. citizen (born or naturalized) who does not hold dual citizenship.
  • You must be able to pass a U.S. federal government Minimum Background Investigation for a Moderate Public Trust position.
  • You should have hands-on experience with security infrastructure such as IDS/IPS, WAFs, firewalls, and antivirus (preferred).
  • You should hold relevant certifications (e.g., Security+, BTL1, GCFA, GCIH) or a degree in Computer Science or Cybersecurity (preferred).

More like this

Similar roles

Senior Incident Responder, Global CSIRT

Salesforce

McLean, VA +1 37 days ago $148,500–$223,900
Incident Response SOAR MITRE ATT&CK AWS Azure GCP CI/CD Malware Analysis Detection Engineering Forensics Linux Windows macOS AI LLM Salesforce Platform SaaS
5+ yrs exp Hybrid

Senior Lead Incident Responder

Salesforce

Seattle, WA 54 days ago
Splunk SQL Regex Salesforce Marketing Cloud Commerce Cloud API AWS GCP Azure Detection Engineering Incident Response GDPR PCI-DSS DORA
8+ yrs exp Hybrid

Senior CSIRT Responder

Adobe

San Jose, CA +2 110 days ago
Incident Response Digital Forensics Log Analysis SIEM EDR IDS/IPS Threat Hunting Cybersecurity

Security Engineer, Incident Response

F5 Inc

Seattle +1 6 days ago $132,000–$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes SIEM EDR CrowdStrike WAF WAAP API Gateway DDoS Mitigation MITRE ATT&CK NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS NGINX BIG-IP
5+ yrs exp Hybrid

Incident Response Lead

Leidos

Washington, DC +1 47 days ago $107,900–$195,050
Incident Response SOC Operations Cybersecurity Analysis Windows Linux Network Architecture Firewalls Proxies Load Balancers VPN DHCP DNS HTTP Cyber Kill Chain Automation Intrusion Detection
8+ yrs exp

Senior Incident Response Analyst

Leidos

Arlington, VA 21 days ago $131,300–$237,350
Incident Response EDR IDS SIEM Python PowerShell Bash Malware Analysis Computer Forensics Windows Linux Firewalls Proxies Load Balancers VPN ATT&CK Framework Cyber Kill Chain FISMA
10+ yrs exp