Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
$111,000–$122,000 year
On-siteHerndon, Virginia, United States
Job Summary
Respond to and investigate cyber security events within Salesforce's SNS Cloud environments, tracking incidents in ticketing systems and analyzing log data for malicious activity using SIEM tools. Coordinate incident response actions for high-priority operations security issues across multi-disciplinary teams, escalating appropriately and providing regular updates to senior leaders. Perform system forensics and investigation by analyzing artifacts for indicators of compromise while automating workflows to apply mitigations against adversary TTPs. Provide periods of 24x7 on-call support on an as-needed basis and occasionally travel to customer sites. This customer-facing role requires a U.S. citizen with an active TS/SCI clearance and polygraph, working on-site in Northern Virginia.
Required Qualifications
- U.S. citizen
- active U.S. Government Top Secret/SCI security clearance with Polygraph
- A related technical degree, such as Computer Science, Software Engineering, Cybersecurity, Information Assurance, or equivalent work experience
- 2+ years experience in cybersecurity, engineering, and/or incident response roles
- Strong interpersonal and communication skills
- Strong problem solving ability
- Strong technical understanding of the information security threat landscape (attack vectors and tools, best practices for securing systems and networks, etc.)
- Experience with AWS Cloud, Splunk, Azure Sentinel, or ElasticStack, etc.
Desired Qualifications
- Technical understanding of the information security threat landscape, to include attack vectors, tools, best practices for securing systems and networks, etc.
- Technical understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.)
- Familiarity with incident response and security operations within cloud environments
- Familiarity with Mac OSX, Microsoft Windows, and Linux/Unix system administration and security controls
- Technical understanding of AWS, Azure, or GCP administration and security controls
- Experience creating and managing event and metric dashboards with tools like Splunk, Kibana, Grafana, etc.
- Experience with data query languages, such as SQL, SPL, GraphQL, etc.
- Scripting language (i.e. Bash, Python, etc.) and workflow automation experience
- Operational experience monitoring devices such as network and host-based intrusion detection systems, web application firewalls, database security monitoring systems, firewalls/routers/switches, proxy servers, antivirus systems, file integrity monitoring tools, and operating system logs
- System forensics/investigation skills, including analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise
- Relevant information security certifications, such as CISSP, GCFR, GCIA, GCIH or other related certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.