Senior Incident Responder, Global CSIRT

Salesforce

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Mclean, VA
Salary
$148,500–$223,900 / yr
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $169k
This role $186k
$120k most similar roles pay here $235k

This role pays more than 64% of similar roles. Most pay $140,062–$197,400 — the shaded band above. At the midpoint, this role pays about $186k versus about $169k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 106 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 98 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Senior Incident Responder, Global CSIRT

As a Senior Incident Responder within the Global CSIRT team, you will perform hands-on technical work to protect company and customer data from adversaries across on-premises and multi-cloud environments. You will investigate security incidents end-to-end, including triage, containment, eradication, and recovery for insider threats, adversary activity, and web application attacks. Your daily responsibilities involve developing playbooks, detection-as-code, and SOAR tooling to improve response times while mentoring junior analysts. The role requires expertise in host and network forensics across Windows, macOS, and Linux systems, as well as experience with AWS, Azure, or GCP cloud architectures and CI/CD pipelines. You must possess a deep understanding of the MITRE ATT&CK framework and TTPs. Key skills include analyzing file system and memory artifacts, managing incident documentation, and utilizing advanced security tools to mitigate complex threats.

What you'll do

  • Investigate and respond to security incidents end-to-end, including triage, containment, eradication, and recovery.
  • Lead high-priority investigations into adversary activity, insider threats, and web application attacks.
  • Perform host and network forensics across Windows, macOS, and Linux environments to identify indicators of compromise.
  • Develop and improve incident response playbooks, detection-as-code, and SOAR tooling to reduce response times.
  • Produce clear incident documentation and status updates for both technical and non-technical stakeholders.
  • Mentor junior incident responders and provide guidance on complex security investigations.
  • Participate in a 24x7x365 on-call rotation to support critical security monitoring and response.

What we're looking for

  • You must have 5+ years of experience in information security, including hands-on operational security monitoring and incident response.
  • You must be able to perform host and network forensics across Windows, macOS, and Linux systems.
  • You must have experience responding to incidents in cloud environments (AWS, Azure, and/or GCP).
  • You must possess a solid understanding of the threat landscape, including TTPs and frameworks like MITRE ATT&CK.
  • You must be able to communicate clearly in writing and verbally while documenting incidents effectively for various stakeholders.
  • Preferred certifications include SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or Offensive Security OSCP.
  • You must be a U.S. citizen (born or naturalized) who does not hold dual citizenship.
  • You must be able to pass a U.S. federal government Minimum Background Investigation (MBI).

More like this

Similar roles

Senior Lead Incident Responder

Salesforce

Remote (Seattle, WA) 24 days ago $172,500$260,100
Splunk SQL Regex API Salesforce Marketing Cloud Commerce Cloud AWS GCP Azure Detection Engineering Incident Response SaaS GDPR PCI-DSS DORA
8+ yrs exp Remote

Lead, Incident Response

Salesforce

Remote (Mclean, VA) 7 days ago $172,500$260,100
Incident Response SOAR Detection-as-Code AWS Azure GCP CI/CD Network Forensics Malware Analysis Detection Engineering MITRE ATT&CK Linux Windows macOS Security Orchestration
8+ yrs exp Remote

Staff Cyber Incident Response Engineer

Adobe

San Jose, CA +2 91 days ago $214,100$310,100
Incident Response Forensics Malware Triage Kubernetes Docker EDR Linux MacOS Windows AWS Azure GCP SIEM Bash Python Ruby Log Analysis Threat Hunting
7+ yrs exp

Senior Incident Handler

Allstate

Remote (IL) 59 days ago $120,000$193,725
Incident Response EDR XDR SIEM Python PowerShell SOAR Malware Analysis Forensic Analysis Threat Hunting Network Security AI Scripting Cybersecurity Operations
5+ yrs exp Remote

Critical Incident Communications Manager

Salesforce

Remote (Bellevue, WA) 7 days ago $117,400$177,600
Incident Management Crisis Communications Technical Writing Salesforce AWS GCP Cloud Infrastructure Database Architecture CRM Project Management Change Management AI
5+ yrs exp Remote