Senior Threat Detection Engineer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job CategoryEnterprise Technology & Infrastructure
Job Details About SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
About the RoleAs a Senior Threat Detection Engineer, you will take full ownership of a technical area, responsible for delivering all necessary research and features to achieve our team's goals. You will collaborate with teams across multiple geographies to deliver on initiatives with many moving parts. Additionally, you will have the opportunity to lead broad initiatives that extend beyond our immediate work. We value innovation and expect everyone to come up with creative solutions to the challenges we and our customers face.
WhatYou Will Be Doing
- Detecting attacks against Salesforce's infrastructure, products, employees, and customers.
- Collaborating with CSIRT and engineering teams to enhance detection effectiveness.
- Writing logic on security platforms to detect malicious activity, building attack simulation scenarios, and testing logic effectiveness.
- Working closely with the incident response team to improve alert reliability and quality.
- Leading projects end-to-end, owning a technical area, and delivering research and features.
- Engaging in security organization-wide initiatives and cross-team collaboration with multiple engineering teams.
- 8+ years of experience in Cyber Security, including at least 6 years of hands‑on experience in Threat Detection, Threat Hunting, Security Incident Response, and managing significant security incidents and breaches.
- Expertise in developing and refining threat detection methodologies, leveraging security logs from various sources, including network infrastructure, endpoint devices, public and private cloud substrates, and SaaS.
- Strong proficiency in log correlation techniques to identify patterns and anomalies indicative of malicious activity. Expertise in constructing complex search queries using languages such as SPL, YARA, and other query languages to analyze large volumes of data.
- In-depth knowledge of fundamental security principles, common attack vectors, Tactics, Techniques, and Procedures (TTPs) used throughout the cyber kill chain, and relevant security frameworks such as the MITRE ATT&CK framework.
Practical experience with a variety of security tools and technologies, including SIEM systems, EDR solutions, NDR tools, and SOAR platforms.
Ability to handle and analyze large and complex datasets, identifying meaningful security insights and trends. Understanding data processing pipelines, performance considerations when querying large datasets, and synthesizing findings into actionable intelligence.
- Hands‑on experience with log aggregation/SIEM tools such as Splunk, Elastic (ELK), FLINK, Chronicle, etc.
- Experience with public cloud security, particularly AWS, Azure, or GCP.
- Undergraduate degree in Cyber Security, Computer Science, Information Technology, or similar fields.
- Experience working in a globally distributed team, leveraging documentation and asynchronous communications.
- Experience with automation platforms such as SOAR.
When you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).