Overview of the Role:

Our Incident and Vulnerability Commanders are a critical part of Salesforce’s Cyber Security Response Center. We own the response to the most impactful cyber security incidents and vulnerabilities across the organization from the definition of the incident response strategy to the final remediation of the threats. Based on our unique perspective on the cyber threat landscape, we can effectively inform Engineering, Security and Business stakeholders with actionable intelligence on key cyber risks and we are empowered to identify and initiate uplift initiatives across the organization to strengthen our security posture. As Salesforce AI Trailblazers, we have access to early-stage GenAI and LLM technologies and we continuously research and test capabilities to reduce the toil and to scale our incident response and vulnerability management capabilities.

The scale of our environment and the impact of problems to solve provide unique opportunities to learn and to... grow surrounded by a diverse and supportive team and partners.

• Lead the response to high severity incidents and vulnerabilities during EMEA shift. Establish a granular response strategy to investigate, contain and mitigate risk; coordinate cross-functionally its timely execution with a sense of urgency.
• Command technical response calls and Leadership briefings; provide structured, concise and factual information of the incident and its response to a technical and non technical audience.
• Contribute to post-mortem reviews and identify high impact technical control gaps and process deficiencies. Directly partner with Engineering, Security and Cloud teams to identify, initiate and implement high-impact mitigation initiatives across the environment.
• Provide key insights on high severity risks to Security and Engineering Leadership; partner directly with Security and Engineering Executive teams to inform the security roadmap and to address recurring risks.
• Continuously identify opportunities to simplify and automate. Actively contribute to the design, planning and execution of the automation roadmap for the response function. Research and test the applicability of available LLM technologies, partner with Engineering to design features and iterate on models.

Hours of operations
• Monday-Friday shift hours (8.30am GMT - 4.30pm GMT)
• Global roster for weekend (1/7 wkds) and public holidays

Required Qualifications:

Successful Incident and Vulnerability Managers thrive on challenge, are calm under pressure, and leverage on their business acumen and cyber technical expertise to drive timely outcomes. Integrity, flexibility and creative problem-solving skills are prerequisites for this role.
• Experience will be evaluated based on alignment to the core competencies for the role (e.g. extracurricular leadership roles, military experience, volunteer work, etc.)
• 5+ years of experience in cyber security operations.
• Ability to stay composed under pressure and to think critically on the spot.
• Demonstrated experience directly leading high severity cyber security incidents in enterprise environments. Practical knowledge of incident response in a cloud environment.
• Excellent verbal and written communication skills; ability to communicate effectively and clearly to technical and non-technical audiences in high pressure situations.
• Project management skills with demonstrated ability to drive, influence and coordinate global and cross functional projects.
• Teamwork mindset with the ability to successfully collaborate in a follow-the-sun model and to grow High Trust relationships across the organization.

Preferred Qualifications:
• Strong technical knowledge of Cloud environments (AWS, GCP, Azure).
• Strong technical knowledge of network fundamentals and common Internet protocols.
• Strong technical knowledge of incident response frameworks with operational experience across Windows, Mac and Linux forensics
• Relevant incident response and cyber security certifications
