Associate Incident Responder, CSIRT

1 Month ago • 2 Years + • Cyber Security

Job Summary

Job Description

As an Associate Incident Responder in Salesforce's Global CSIRT, you'll be on the front lines of the production environment. Responsibilities include contributing to CSIRT projects, conducting threat hunts, and improving workflows and processes. This role requires 24x7x365 availability based on a 'follow the sun' operating model. You'll work with various security tools and technologies, collaborating with internal and external teams to protect company and customer data. Strong communication skills and a deep understanding of incident response, network fundamentals, and cloud security are essential.
Must have:
  • 2+ years security operations experience
  • EDR (e.g., Crowdstrike) experience
  • Log analysis (Splunk, etc.) experience
  • Strong communication skills
  • Understanding of incident response
  • Network & cloud security knowledge
Good to have:
  • Understanding of threat landscape
  • Global team collaboration experience
  • Scripting (Python, Bash, etc.)
  • Security certifications (BTL1, SANS GCIH, etc.)

Job Details

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Enterprise Technology & Infrastructure

Job Details

About Salesforce

We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer, too — driving your performance and career growth, charting new paths, and improving the state of the world. If you believe in business as the greatest platform for change and in companies doing well and doing good – you’ve come to the right place.

Salesforce has one of the best Information Security teams in the world and growing this piece of the business is a top priority! Our Information Security teams work hand in hand with the business to ensure the highest security around all of our applications and infrastructure. CSIRT is a geographically distributed team, responsible for 24x7x365 security monitoring and rapid incident response across all Salesforce environments. We are the ‘tip of the spear’ protecting company and customer data from our adversaries.

As a key member of our growing Global CSIRT, the Associate Incident Responder is on the ‘front lines’ of the Salesforce production environment; You will be contributing to CSIRT projects, conducting threat hunts and improving core CSIRT workflows and processes.

Working hours correspond to our “follow the sun” operating model and shift according to daylight savings during the year. Applicants must meet all visa requirements to work and live in Australia.

 

REQUIRED SKILLS:

Min 2 years of prior specialised security operations experience consisting of:

  • Flexibility, drive, integrity, and creative problem-solving skills

  • Operational experience with Endpoint Detection and Response (EDR) solutions i.e. Crowdstrike etc.

  • Operational experience with log analysis platforms i.e. Splunk, Google Security Operations, Kibana etc.

  • The ability to build strong relationships with peers both internal and external to your functional group, and with peers/professional organisations outside your company

  • Strong verbal and written communication skills; ability to communicate effectively and clearly to both technical and non-technical audiences

  • Familiarity with core concepts of security incident response, e.g., the typical phases of response, vulnerabilities vs threats vs actors, Indicators of Compromise (IoCs), etc.

  • Understanding of network fundamentals and common Internet protocols, specifically DNS, HTTP, HTTPS/TLS, and SMTP

  • Understanding of cloud security principles and experience with public cloud (e.g. AWS, Azure, or GCP)

  • Understanding of Mac OSX, Microsoft Windows, and Linux/Unix system administration and security control fundamentals

  • Strong interest in information security, including awareness of current threats and security best practices

  • Knowledge of email security threats and security controls, including analyzing email headers

DESIRED SKILLS:

  • Understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.)

  • Previous experience of collaborating with global teams

  • Working proficiency with programming /scripting languages is a plus: i.e. Python, Bash, Go, PowerShell

  • Relevant information security certifications, such as: BTL1, SANS GCIH, GCFA, GCFE, GX-IH, GX-FA and other related certifications

Accommodations

If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form.

Posting Statement

At Salesforce we believe that the business of business is to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects society through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more. Learn more about Equality at www.equality.com and explore our company benefits at www.salesforcebenefits.com.

Salesforce is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Salesforce does not accept unsolicited headhunter and agency resumes. Salesforce will not pay any third-party agency or company that does not have a signed agreement with Salesforce.

Salesforce welcomes all.

Similar Jobs

Synamedia - Software Engineer (Node JS, GoLang, AWS)

Synamedia

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Playrix - Senior Release Engineer

Playrix

Armenia (Remote)
3 Months ago
Unity - Senior DevOps Engineer

Unity

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
4 Months ago
Luxoft - Senior C++ Developer

Luxoft

Poland, Ohio, United States (Remote)
1 Month ago
Tekion Corp - Security Engineer II

Tekion Corp

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
PwC - Forensic Service Director (Bilingual FR/EN)

PwC

Montreal, Quebec, Canada (On-Site)
4 Months ago
Logifuture - Information Security Manager

Logifuture

Ta' Xbiex, Malta (Hybrid)
3 Months ago
Zuora - Sr Security Engineer

Zuora

Chennai, Tamil Nadu, India (Hybrid)
3 Months ago
Unity - Senior Security Operations Engineer

Unity

Montreal, Quebec, Canada (On-Site)
1 Month ago
Balbix - Senior Customer Success Manager

Balbix

San Jose, California, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Playrix - Lead QA Engineer (Resources Team)

Playrix

Montenegro (Remote)
3 Months ago
Saviynt - Engineer, CloudOps

Saviynt

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Garena - Senior/Expert Engineer, Site Reliability (SRE)

Garena

Singapore (On-Site)
3 Months ago
 Sagecor Solutions - Software Engineer 3 (IDN - 075)

Sagecor Solutions

Annapolis Junction, Maryland, United States (On-Site)
3 Months ago
Eleven Labs - Compliance Engineer

Eleven Labs

London, England, United Kingdom (Remote)
3 Months ago
ION - Senior DevSecOps Engineer, Italy

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
4 Months ago
Playrix - Lead QA Engineer (Resources Team)

Playrix

Ireland (Remote)
3 Months ago
WebPT - Senior DevOps Engineer

WebPT

Hyderabad, Telangana, India (Hybrid)
4 Months ago
Playrix - Senior Release Engineer

Playrix

Cyprus (Remote)
3 Months ago
Thatgamecompany - DevOps Engineer - Shanghai

Thatgamecompany

Shanghai, Shanghai, China (On-Site)
8 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Sydney, New South Wales, Australia

Canva - Engineering Manager (BE) - Media Platform (Remote across ANZ)

Canva

Melbourne, Victoria, Australia (Remote)
1 Month ago
Easygo - Data and Analytics Manager

Easygo

Melbourne, Victoria, Australia (On-Site)
4 Months ago
Tesla - Utility Service Technician, Koorangie

Tesla

Victoria, Australia (On-Site)
1 Month ago
Easygo - Junior Brand Designer

Easygo

Melbourne, Victoria, Australia (On-Site)
4 Months ago
Framestore - Junior Data Operations Technician

Framestore

Melbourne, Victoria, Australia (Hybrid)
2 Months ago
Canva - Brand Program Manager (2 Months)

Canva

Sydney, New South Wales, Australia (Remote)
1 Month ago
Tesla - Vehicle Technician, Alexandria

Tesla

New South Wales, Australia (On-Site)
1 Month ago
Trek - Production Technician

Trek

Rouse Hill, New South Wales, Australia (On-Site)
2 Months ago
Tesla - Associate Energy Systems Technical Support Engineer

Tesla

Victoria, Australia (On-Site)
1 Month ago
Aristocrat Gaming - Warehouse Storeperson

Aristocrat Gaming

Victoria, Australia (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Granicus - Cloud Network Security Engineer

Granicus

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Axinous - Senior Global Health and Safety Manager

Axinous

Escazu, San José Province, Costa Rica (Hybrid)
3 Months ago
PwC - AES SAP Security Manager - Operate

PwC

Hyderabad, Telangana, India (On-Site)
4 Months ago
Omnissa - Member of technical staff (Appsecurity, Pentesting)

Omnissa

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Microsoft - Director, Cybersecurity Policy and Diplomacy

Microsoft

Belgium (On-Site)
1 Month ago
OKX - IT Security Operations

OKX

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (Hybrid)
4 Months ago
PwC - AES Guidewire Lead Integration Developer Senior Associate Operate

PwC

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Google - Customer Engineer, Federal Civilian, Public Sector

Google

Reston, Virginia, United States (On-Site)
1 Month ago
Microsoft - SECURITY SERVICE ENGINEER II

Microsoft

Hyderabad, Telangana, India (On-Site)
1 Month ago
Axinous - Android Software Engineer (Networking)

Axinous

San Jose, California, United States (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded