Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
$111,000–$122,000 year
On-siteHerndon, Virginia, United States
Job Summary
Respond to and investigate cyber security events within Salesforce National Security Cloud environments, tracking incidents in ticketing systems and analyzing log data in a SIEM for malicious activity. Coordinate incident response actions for high-priority operations security issues, escalate appropriately, and provide regular updates to senior leaders while meeting service-level agreements. Work across multi-disciplined teams to drive resolution, automate workflows, develop analytics, and hunt for undetected indicators of compromise using tactics, techniques, and procedures. Provide periods of 24x7 on-call support on an as-needed basis and occasionally travel to customer sites. This role supports the Infrastructure Security Team protecting critical infrastructure and customer data from information security threats.
Required Qualifications
- U.S. citizen
- active U.S. Government Top Secret/SCI security clearance with Polygraph
- A related technical degree, such as Computer Science, Software Engineering, Cybersecurity, Information Assurance, or equivalent work experience
- 2+ years experience in cybersecurity, engineering, and/or incident response roles
- Strong interpersonal and communication skills
- Strong problem solving ability
- Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.)
- Experience with AWS Cloud, Splunk, Azure Sentinel, or ElasticStack, etc.
Desired Qualifications
- Technical understanding of the information security threat landscape, to include attack vectors, tools, best practices for securing systems and networks, etc.
- Technical understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.)
- Familiarity with incident response and security operations within cloud environments
- Familiarity with Mac OSX, Microsoft Windows, and Linux/Unix system administration and security controls
- Technical understanding of AWS, Azure, or GCP administration and security controls
- Experience creating and managing event and metric dashboards with tools like Splunk, Kibana, Grafana, etc.
- Experience with data query languages, such as SQL, SPL, GraphQL, etc.
- Scripting language (i.e. Bash, Python, etc.) and workflow automation experience
- Operational experience monitoring devices such as network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools, and operating system logs
- System forensics/investigation skills, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise
- Relevant information security certifications, such as CISSP, GCFR, GCIA, GCIH or other related certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.