> Markdown version of [/jobs/ext/1387782-computer-security-incident-report-analyst-with-ts-sci-clearance-salesforce-national-security](https://www.wearedevelopers.com/jobs/ext/1387782-computer-security-incident-report-analyst-with-ts-sci-clearance-salesforce-national-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security] - **Company:** Salesforce Inc. - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $111,000.0 - $122,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Proxy Servers, Antivirus Softwares, Apple Mac Systems, Application Firewall, Application Layers, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Query Languages, Database Security, File Systems, Domain Name System (DNS), Monitoring of Systems, Hypertext Transfer Protocols (HTTP), Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Simple Mail Transfer Protocols, Network Connections, Reverse Engineering, Salesforce.Com, Security Information and Event Management, Software Engineering, SQL Databases, TCP/IP, Network Routers, Scripting, Cloud Platform System, Grafana, Malware, Firewalls (Computer Science), Information Technology, Graphql, Kibana, Splunk, Vulnerability Analysis - **Published:** July 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e8f66f9a995dfa39 ## About the Role The candidate must be a U.S. citizen and must have an active U.S. Government Top Secret/SCI security clearance with Polygraph. * A related technical degree, such as Computer Science, Software Engineering, Cybersecurity, Information Assurance, or equivalent work experience. * 2+ years experience in cybersecurity, engineering, and/or incident response roles. * Strong interpersonal and communication skills required for coordinating responses to sophisticated incidents across the organization with many non technical and technical stakeholders. * Strong problem solving ability to determine solutions to encountered or anticipated challenges. * Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.). * Experience with AWS Cloud, Splunk, Azure Sentinel, or ElasticStack, etc. preferred. Desired Skills: * Technical understanding of the information security threat landscape, to include attack vectors, tools, best practices for securing systems and networks, etc. * Technical understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.). * Familiarity with incident response and security operations within cloud environments. * Familiarity with Mac OSX, Microsoft Windows, and Linux/Unix system administration and security controls. * Technical understanding of AWS, Azure, or GCP administration and security controls. * Experience creating and managing event and metric dashboards with tools like Splunk, Kibana, Grafana, etc. * Experience with data query languages, such as SQL, SPL, GraphQL, etc. * Scripting language (i.e. Bash, Python, etc.) and workflow automation experience. * Operational experience monitoring devices such as network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools, and operating system logs. * System forensics/investigation skills, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise. * Relevant information security certifications, such as CISSP, GCFR, GCIA, GCIH or other related certifications. This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.This position requires a USA TS/SCI with Polygraph security access level. This position requires a USA TS/SCI with Polygraph security access level. ## Description Computer Security Incident Response Analyst This is a customer-facing role and will require you to be on-site in Northern Virginia. This is NOT a remote position. Salesforce - the leader in enterprise cloud computing and one of the top 10 places to work according to Fortune magazine - is seeking an Incident Response Analyst for our Government Cloud Security Operations team. As part of the Salesforce National Security (SNS) Infrastructure Security Team, the Incident Response Analyst will work on the 'front lines' of Salesforce environments supporting US Government agencies and departments performing national security functions. The Infrastructure Security Team, protects our critical infrastructure and our customers' data from the latest information security threats. The team is responsible for 24x7x365 security monitoring, security operations, real-time analysis of security alert data, and rapid incident response across SNS Cloud environments. PLEASE NOTE: Qualification for this job is contingent upon acceptable results from a background investigation as well as your having and maintaining the specific level of U.S. government background investigation and clearance required for this role. Role Description: The Incident Response Analyst will respond to and investigate cyber security events within the SNS Cloud environments, track and document security events and incidents in a ticketing system, and analyze log data for signs of malicious activity in a Security Information and Event Manager (SIEM). The Analyst will need to work across multi-disciplined teams to coordinate incident response actions for high-priority, high-transparency operations security issues to drive toward a resolution while meeting required service-level agreements, escalating as appropriate, and providing regular updates to senior leaders. This position offers a challenging opportunity to be exposed to a diverse set of security disciplines, including incident response, forensics, reverse engineering, malware analysis, intrusion detection, network security, and system security. This position provides opportunities to automate workflows and processes, develop new analytics and apply mitigations for adversary Tactics, Techniques, and Procedures (TTPs), and hunt for undetected indicators of compromise. This position may require you to provide periods of 24x7 on-call support on an as-needed basis. As we work with Government customers, this position may require occasional local travel to customer sites. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Debug a Kubernetes Operator](https://www.wearedevelopers.com/videos/487-debug-a-kubernetes-operator) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)