To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Software Engineering
Job Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
The Experience:
As a Senior Threat Intelligence Researcher (Production), you don't just track threats—you contextualize and produce organic intelligence about them. You are a key pillar of the Threat Intelligence (TI) team, specifically focused on intelligence production across our suite of products and threat actors we track. You will lead the charge in translating nuanced technical intelligence and actor tracking operations into synthesized intelligence products for a wide and diverse audience. Your work will directly support other aspects of TI’s threat actor tracking and disruption work, informing the business to take action that imposes friction on threat actors targeting the Salesforce ecosystem. This is a role where you need to have a baseline technical capability and proven intelligence analysis skills—you are already well-versed at producing various intelligence products in written form and you have proven expertise in briefing to multiple audiences, running from technical to executive. You will analyze new and emerging threats to Salesforce, our platforms, and our customers, and turn that intelligence into action. Crucial to this work is directly engaging TI customers across key phases of the Threat Intelligence Lifecycle—shaping planning & direction, executing dissemination, and soliciting feedback to continuously refine intelligence output. You also understand the value of Community engagement and will participate in not just disseminating intelligence internally but also sharing the nuance of our work within the broader Threat Community.
This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role.
What You'll Actually Be Doing
Lead technical pipeline development of capabilities focused on creation and delivery of intelligence products.
Maintain and enhance Salesforce TI’s threat prioritization model to continually identify top threats to Salesforce.
Coordinate and manage creation, organization, development, and delivery of threat intelligence quarterly briefings to senior security and company leadership.
Serve as one of the primary team interfaces with threat intelligence customers, managing educational presentations and incorporating feedback into threat intelligence capability development.
Lead the development of routine and ad hoc threat intelligence written products, and own the customer dissemination portfolio for the team.
Consume and curate threat data to create intelligence assessments in support of our incident response, threat hunting, threat detection, security engineering, and risk prioritization missions.
Consume and curate OSINT and paid-for vendor reporting to contextualize the threat landscape.
Write scripts (or capability to learn how to) and tools to help with analysis and build automation to aid investigations and threat research using lessons learned.
Build expertise on any threats targeting Salesforce and provide attribution to attacker activity when possible
Identify new and existing threats and clearly distill this information to support finished intelligence to multiple internal partners, including executives.
Perform intelligence research during incident response, supporting multiple teams and drive direction of investigations based on knowledge of attackers.