> Markdown version of [/jobs/ext/2297983-lead-incident-responder-csirt](https://www.wearedevelopers.com/jobs/ext/2297983-lead-incident-responder-csirt). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Incident Responder, CSIRT - **Company:** Salesforce.com, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $172,500.0 - $260,100.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Delivery, Continuous Integration, Customer Data Management, Linux, File Systems, Network Connections, Salesforce.Com, Web Applications, Data Logging, Google Cloud, Cloud Platform System, Malware, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88177856/1 ## About the Role * You have 8+ years of experience in information security, including operational security monitoring and incident response. * You have system forensics and investigation skills across Windows, Mac OS X, and Linux, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise. * You have strong technical understanding of the information security threat landscape, including attack vectors, tools, and best practices for securing systems and networks. * You communicate clearly and effectively with executive leadership, both verbally and in writing. Even Better If... * You're a subject matter expert in a domain such as malware analysis, detection writing, forensics, cloud security, or offensive security. * You have experience responding to security incidents in cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud), including familiarity with relevant architectures, continuous integration/continuous delivery (CI/CD), and logging. * You have prior experience in a 24x7x365 operations environment. * You've driven automation and capability uplift through tool development, artificial intelligence, or security orchestration, automation, and response (SOAR) platforms. * You hold relevant information security certifications, such as SANS GCIH, SANS GPEN, SANS GFCA, or Offensive Security OSCP. This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position. ## Description Salesforce is seeking a Lead Incident Responder for our GovCloud Computer Security Incident Response Team (CSIRT). The CSIRT provides 24x7x365 security monitoring and rapid incident response across all Salesforce environments. This role focuses on the US Federal Risk and Authorization Management Program (FedRAMP) environment, acting as the last line of defense protecting company and customer data from adversaries. This position sits within the AMERS CSIRT, supporting the US GovCloud environment. On-call work, including evenings and weekends, is required as needed. Core hours are 10:30 AM - 6:30 PM EST, Monday through Friday. What You'll Actually Be Doing * Manage the response to high-severity security incidents and act as a technical escalation point for the Incident Responder team. * Lead cross-functional response to high-priority, high-visibility security issues, including insider investigations, advanced adversaries, and web application attacks. * Drive process improvement and automation for detection and incident response capabilities. * Lead strategic projects that enhance detection and response capabilities within the environment. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)