Principal Insider Threat Analyst

Salesforce Salesforce · Enterprise · McLean, VA +2

Principal Insider Threat Analyst role at Salesforce, focusing on maturing the Insider Threat Program. Responsibilities include conducting complex investigations, architecting threat hunting operations, evolving the program model, and contributing to risk assessments. Requires deep technical skills in cybersecurity, incident response, and insider threat, along with program leadership experience.

What you'd actually do

  1. Be Salesforce’s subject matter expert in insider threat.
  2. Conduct investigations into the most complex and sensitive insider-threat matters across all of Salesforce. You will own the investigation from initial signal through evidence preservation, timeline reconstruction, interview support, documentation, and handoff to partner teams.
  3. Architect proactive threat hunting operations for insiders and translate the results of those hunts into investigations and high fidelity detections.
  4. Evolve and maintain the model for a world class insider threat analysis program. You will identify tooling and coverage gaps, metrics, and where to invest next. You’ll be building and maintaining the processes and playbooks the team uses.
  5. Contribute to risk assessments for crown jewel analysis, high-sensitivity roles, M&A activity

Skills

Required

  • Cybersecurity
  • Incident Response
  • Intelligence
  • Insider Threat
  • Counterintelligence
  • Program Leadership
  • Technical Skills
  • Detections
  • Hunts
  • Investigations
  • Program Leadership
  • Risk Assessments
  • Communication Skills
  • Relationship Building

Nice to have

  • Insider Threat Program development
  • Detection frameworks
  • Cross-functional governance models
  • Cloud-based software/platform investigation
  • SaaS/PaaS familiarity

What the JD emphasized

  • 12+ years experience in cybersecurity, incident response, intelligence, insider threat or counterintelligence, with at least 5+ years leading and managing insider threat and/or counterintelligence investigations
  • Deep knowledge of procedures and indicators of malicious insider threat activity such as fraud, theft, sabotage, espionage, etc.
  • Ability to identify and build new capabilities or processes as the scaling needs arise
  • Demonstrated experience creating and employing effective strategies at scale
  • Experience building or maturing a formal Insider Threat Program (InTP) from the ground up, including developing playbooks, detection frameworks, and cross-functional governance models — ideally in a corporate or government environment