Airkit logo

Lead Incident Responder, CSIRT

Airkit

Washington, DCRemoteOtherNo compensation foundPosted todayVerified open today

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Washington, DCRemote
Schedule
Other
Work Authorization
US work authorization required

Requirements

Credentials this posting asks for.

Public Trust clearance

Job overview

Salesforce seeks a Lead Incident Responder for its GovCloud CSIRT, providing 24x7 monitoring and rapid response for US Federal FedRAMP environments, acting as the final defense for company and customer data while supporting high‑severity incidents and leading cross‑functional security initiatives.

Skills & qualifications

RequiredNice to have

Skills

Incident ResponseForensic SciencesMac OS XLinuxAutomationGoogle CloudAmazon Web ServicesMicrosoft AzureCI/CDLoggingSOARMalware AnalysisCloud SecurityOffensive SecuritySANS GCIHSANS GPENSANS GFCAOSCP

Qualifications

8+ Years Information Security ExperienceU.S. CitizenshipMinimum Background Investigation for Moderate Public Trust

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Parental Leave
401(k) Match
Paid Time Off

Full job description

Description The Experience

Salesforce is seeking a Lead Incident Responder for our GovCloud Computer Security Incident Response Team (CSIRT). The CSIRT provides 24x7x365 security monitoring and rapid incident response across all Salesforce environments. This role focuses on the US Federal Risk and Authorization Management Program (FedRAMP) environment, acting as the last line of defense protecting company and customer data from adversaries.

This position sits within the AMERS CSIRT, supporting the US GovCloud environment. On-call work, including evenings and weekends, is required as needed. Core hours are 10:30 AM - 6:30 PM EST, Monday through Friday.

What You'll Actually Be Doing

  • Manage the response to high-severity security incidents and act as a technical escalation point for the Incident Responder team.
  • Lead cross-functional response to high-priority, high-visibility security issues, including insider investigations, advanced adversaries, and web application attacks.
  • Drive process improvement and automation for detection and incident response capabilities.
  • Lead strategic projects that enhance detection and response capabilities within the environment.

You're Our Person If...

  • You have 8+ years of experience in information security, including operational security monitoring and incident response.
  • You have system forensics and investigation skills across Windows, Mac OS X, and Linux, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise.
  • You have strong technical understanding of the information security threat landscape, including attack vectors, tools, and best practices for securing systems and networks.
  • You communicate clearly and effectively with executive leadership, both verbally and in writing.

Even Better If...

  • You're a subject matter expert in a domain such as malware analysis, detection writing, forensics, cloud security, or offensive security.
  • You have experience responding to security incidents in cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud), including familiarity with relevant architectures, continuous integration/continuous delivery (CI/CD), and logging.
  • You have prior experience in a 24x7x365 operations environment.
  • You've driven automation and capability uplift through tool development, artificial intelligence, or security orchestration, automation, and response (SOAR) platforms.
  • You hold relevant information security certifications, such as SANS GCIH, SANS GPEN, SANS GFCA, or Offensive Security OSCP.

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position. In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

You've read the whole posting — now see how you match it.