Information Security Architect - Csirt

Salesforce Salesforce · Enterprise · Seattle, WA

Salesforce is seeking an Information Security Architect for their CSIRT team. This role involves leading cyber security response for commercial and GovCloud environments, acting as an executive liaison, and driving continuous improvement initiatives. The candidate must be a U.S. citizen operating on U.S. soil and meet government screening standards.

What you'd actually do

  1. Act as the Incident or Vulnerability Commander for Salesforce’s high risk cyber security events across our Commercial and GovCloud environments.
  2. Establish response strategy and coordinate its delivery until remediation of threats.
  3. Ensure the highest standards of the execution and documentation of the NIST incident response lifecycle to timely scope, contain and remediate critical security threats.
  4. Command Executive Briefings and response calls, act as security executive liaison.
  5. Maintain timely communications on progress and findings to Leadership and address incoming escalations from executives.

Skills

Required

  • 5+ years of relevant experience in security operations, incident management and/or risk management within an enterprise environment.
  • A related technical degree required.
  • Experience responding to and leading complex critical cyber security incidents in a large-scale environment.
  • Broad knowledge of security best practices, the current threat landscape and the incident response lifecycle.
  • Strong teamwork skills with the ability to build and grow relationships.
  • Ability to stay composed under pressure and to think critically on the spot.
  • Excellent verbal and written communication skills; ability to communicate optimally and clearly to both technical and non-technical audiences.
  • Project management skills with proven ability to drive, influence and coordinate cross-teams and cross-region projects.

Nice to have

  • Technical knowledge of complex systems and Cloud environments (AWS, GCP, Azure).
  • Technical knowledge of network fundamentals and common Internet protocols.
  • Technical knowledge of incident response frameworks with operational experience across Windows, Mac and Linux forensics
  • Operational and services experience in a cloud services delivery environment
  • Experience in conducting root cause analysis
  • Familiarity with cyber key security regulations and standards (e.g.,NIST, PCI-DSS, GDPR, ISO 27001)
  • Relevant information security certifications

What the JD emphasized

  • U.S. citizen
  • does not hold dual citizenship
  • operating on U.S. Soil
  • meet customer and government screening standards
  • Minimum Background Investigation (MBI)