Senior Threat Detection Engineer
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action, tech meets trust, and innovation is a way of life. We're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
About the role
As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area, responsible for delivering all necessary research and features to achieve our team’s goals in that area. You will work across teams in multiple geographies to deliver on initiatives with many moving parts and lead broad initiatives that go beyond our own work. We value innovation and expect everyone to come up with creative ways to solve the problems that we and our customers face.
Responsibilities
- Lead a project end-to-end, owning a technical area and delivering research and features.
- Write logic on security platforms to detect malicious activity, build attack simulation scenarios, and test logic effectiveness.
- Collaborate with the incident response team to improve alert reliability and quality.
- Work on security organization-wide initiatives and cross-team collaboration with multiple engineering teams.
- Develop and refine threat detection methodologies leveraging security logs from multiple sources (network infrastructure, endpoint devices, public/private cloud substrates, SaaS).
- Construct complex search queries using languages such as SPL, YARA, and other query languages to analyze large volumes of data.
- Interpret query results, identify false positives, and fine-tune detection rules for optimal efficacy.
- Correlate multiple log sources for effective adversary detection.
- Handle and analyze large, complex datasets to identify security insights and trends.
- Collaborate across global, cross-functional teams with members in multiple time zones.
Requirements
- 6 to 8 years of experience in Threat Detection, Threat Hunting, Security Incident Response, and managing significant security incidents and breaches.
- Comprehensive grasp of log structure, data normalization techniques, and the capacity to isolate critical security incidents.
- Strong proficiency in log correlation techniques to identify patterns and anomalies indicative of malicious activity.
- In-depth knowledge of fundamental security principles, common attack vectors, TTPs (Tactics, Techniques, and Procedures), and relevant security frameworks such as the MITRE ATT&CK framework.
- Practical experience with security tools and technologies, including SIEM systems, EDR solutions, NDR tools, and SOAR platforms.
- Experience with correlation and complex log analytic queries.
- Coding experience with Python or other languages for automation.
- Ability to correlate multiple log sources for effective adversary detection.
- Demonstrated experience collaborating across global, cross-functional teams.
- A related technical degree (e.g., cyber security, computer science, information technology).
Preferred Qualifications
- Hands-on experience with log aggregation/SIEM tools such as Splunk, Elastic (ELK), Flink, or Chronicle.
- Hands-on experience with public cloud (AWS, Azure, GCP), especially public cloud security.
- Experience working in a globally distributed team leveraging documentation and async communications.
- Prior experience or basic knowledge of data science algorithms and methodologies.
- Experience with automation platforms such as SOAR.
Benefits
- Time off programs.
- Medical, dental, vision, and mental health support.
- Paid parental leave.
- Life and disability insurance.
- 401(k) and employee stock purchasing program.
Pay
The typical base salary range for this position is $148,500 - $223,900 annually. The range represents base salary only and does not include company bonus, incentive for sales roles, equity, or benefits, as applicable.