To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & Infrastructure
Job Details
About Salesforce
As a key member of our growing Global CSIRT, the Senior Incident Responder is on the front lines of the Salesforce production environment; leading a group of incident responders that protect our critical infrastructure and our customers data from the latest information security threats. You will be contributing to significant CSIRT projects, conducting threat hunts, enhancing detection and incident response capabilities, and improving core CSIRT workflows and processes.
Working hours correspond to our follow the sun operating model and shift according to daylight savings during the year. This is a full-time position, based in Hyderabad or Bangalore, hybrid Office-flex , set shift work position. Shifts begin no earlier than 04:00am (IST), and include one fixed weekend shift.
REQUIRED SKILLS:
5+ years of prior specialised security operations experience consisting of:
Flexibility, drive, integrity, and creative problem-solving skills
Operational experience performing incident response with Endpoint Detection and Response (EDR) solutions i.e. Crowdstrike etc.
Operational experience with log analysis platforms i.e. Splunk, Google Security Operations etc.
The ability to build strong relationships with peers both internal and external to your functional group, and with peers/professional organisations outside your company
Customer-centric attitude and focus on providing best-in-class service for customers and stakeholders
The willingness to apply yourself to learning new skills and gaining certifications
Strong verbal and written communication skills; ability to communicate effectively and clearly to both technical and non-technical audiences
Operational experience responding to security incidents in a production environment, such as investigating and remediating large scale network compromise, possible endpoint malware infections and attacker enterprise tactics
Familiarity with core concepts of security incident response, e.g., the typical phases of response, vulnerabilities vs threats vs actors, Indicators of Compromise (IoCs), etc.
Understanding of network fundamentals and common Internet protocols, specifically DNS, HTTP, HTTPS/TLS, and SMTP
Understanding of incident response and security operations within public cloud environments (e.g. AWS, Azure, or GCP)
Understanding of Mac OSX, Microsoft Windows, and Linux/Unix system administration and security control fundamentals
Experience in being part of a project team - demonstrating ability to contribute to projects across teams where influencing skills are required
Previous experience of collaborating with global teams
DESIRED SKILLS:
Understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.)
Working proficiency with programming /scripting languages is a plus: i.e. Python, Bash, Go, PowerShell. Formal development experience would be highly sought after.
Working knowledge of malware reverse engineering
Relevant information security certifications, such as: BTL1, ISC2 CISSP, E-Council E|CIH, SANS GCIH, GCFA, GCFE, GX-IH, GX-FA and other related certifications
#LI-Y
Accommodations
If you require assistance due to a disability applying for open positions please submit a request via this Accommodations Request Form .
Posting Statement
Job Classification
Industry: InternetFunctional Area / Department: IT & Information SecurityRole Category: IT SupportRole: IT Support - OtherEmployement Type: Full time