Lead Vulnerability Commander

Salesforce

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
VA
Salary
$172,500–$260,100 / yr
Posted
32 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $216k
$117k most similar roles pay here $275k

This role pays more than 78% of similar roles. Most pay $151,475–$215,000 — the shaded band above. At the midpoint, this role pays about $216k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 106 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 98 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Lead Vulnerability Commander

As a Lead Vulnerability Commander on the Vulnerability Management team, you will own the end-to-end response to critical vulnerabilities within Commercial and GovCloud environments. You will act as a security executive liaison, engaging engineering teams to brief them on required fixes, tracking cases against strict SLAs, and escalating risks to leadership when necessary. Your daily work involves running retrospectives to drive process improvements, conducting tabletop exercises, and building playbooks and agentic automation to streamline workflows. The role requires expertise in vulnerability management, incident response, and security operations. You will utilize skills in risk assessment, cross-team coordination, and technical communication. Preferred qualifications include knowledge of cloud environments like AWS, GCP, and Azure, as well as experience with network fundamentals, common internet protocols, and forensics across Windows, Mac, and Linux systems to address rapid exploitation risks from frontier AI models.

What you'll do

  • Own the end-to-end response for critical vulnerabilities by engaging engineering teams and driving fixes to completion.
  • Brief engineering owners on required fixes and 24-hour expectations in coordination with security stakeholders.
  • Track cases against SLAs and escalate risks to leadership when deadlines are at risk.
  • Conduct post-incident retrospectives to identify systemic causes and drive improvements in process and tooling.
  • Partner with Threat Intelligence and Product Security teams to determine if vulnerabilities meet specific criteria.
  • Report volume, response times, and SLA adherence metrics to security and engineering leadership.
  • Run tabletop exercises and readiness drills to ensure teams can respond quickly to critical findings.
  • Build playbooks and implement agentic automation to streamline the vulnerability management process.

What we're looking for

  • Must be a U.S. citizen (born or naturalized) without dual citizenship who can meet government screening standards.
  • 8+ years of experience in vulnerability management, incident response, security operations, or a related field.
  • Proven track record of coordinating cross-team remediation under tight deadlines and managing SLA tracking.
  • Strong understanding of vulnerability severity, exploitability, and the triage process for critical findings.
  • Ability to engage engineering teams and hold stakeholders to deadlines without formal authority over them.
  • Excellent written and verbal communication skills to translate technical status into clear risk assessments for leadership.
  • Experience using or building AI-driven tooling for security triage, investigation, or decision support.
  • Technical knowledge of cloud environments (AWS, GCP, Azure), network fundamentals, and incident response frameworks (preferred).

More like this

Similar roles

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 53 days ago $125,000$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Staff Vulnerability Management Engineer

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Vulnerability Management Python Go JavaScript TypeScript Java Kubernetes AWS GCP Azure CI/CD Infrastructure as Code SAST SCA SBOM Tines Wiz Semgrep Snyk Rapid7 Tenable Checkmarx CVSS EPSS CISA KEV AI/ML

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 7 days ago $124,800$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Senior Incident Responder, Global CSIRT

Salesforce

Remote (Mclean, VA) 7 days ago $148,500$223,900
Incident Response SOAR CI/CD AWS Azure GCP Windows macOS Linux Malware Analysis Detection Engineering Forensics AI LLM Salesforce Platform SaaS
5+ yrs exp Remote

Lead, Incident Response

Salesforce

Remote (Mclean, VA) 7 days ago $172,500$260,100
Incident Response SOAR Detection-as-Code AWS Azure GCP CI/CD Network Forensics Malware Analysis Detection Engineering MITRE ATT&CK Linux Windows macOS Security Orchestration
8+ yrs exp Remote