Senior Threat Intelligence Researcher

Posted 2 Days Ago
Be an Early Applicant
2 Locations
In-Office
149K-224K Annually
Senior level
Cloud • Software
If you’re ready to build your future — and the future of technology — then you’re in the right place.
The Role
Leads cyber threat intelligence production, including threat research, actor tracking, prioritization, written assessments, executive briefings, and customer dissemination. Develops intelligence pipelines, scripts, automation, and analytical capabilities; supports incident response, threat hunting, detection, engineering, and risk prioritization. Uses OSINT, vendor reporting, and proprietary data to identify and attribute threats, translate findings into actionable recommendations, and engage internal and external intelligence communities.
Summary Generated by Built In

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.

Job Category

Software Engineering

Job Details

About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience:

As a Senior Threat Intelligence Researcher (Production), you don't just track threats—you contextualize and produce organic intelligence about them. You are a key pillar of the Threat Intelligence (TI) team, specifically focused on intelligence production across our suite of products and threat actors we track. You will lead the charge in translating nuanced technical intelligence and actor tracking operations into synthesized intelligence products for a wide and diverse audience. Your work will directly support other aspects of TI’s threat actor tracking and disruption work, informing the business to take action that imposes friction on threat actors targeting the Salesforce ecosystem. This is a role where you need to have a baseline technical capability and proven intelligence analysis skills—you are already well-versed at producing various intelligence products in written form and you have proven expertise in briefing to multiple audiences, running from technical to executive. You will analyze new and emerging threats to Salesforce, our platforms, and our customers, and turn that intelligence into action. Crucial to this work is directly engaging TI customers across key phases of the Threat Intelligence Lifecycle—shaping planning & direction, executing dissemination, and soliciting feedback to continuously refine intelligence output. You also understand the value of Community engagement and will participate in not just disseminating intelligence internally but also sharing the nuance of our work within the broader Threat Community.

This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role.

What You'll Actually Be Doing

  • Lead technical pipeline development of capabilities focused on creation and delivery of intelligence products.

  • Maintain and enhance Salesforce TI’s threat prioritization model to continually identify top threats to Salesforce.

  • Coordinate and manage creation, organization, development, and delivery of threat intelligence quarterly briefings to senior security and company leadership.

  • Serve as one of the primary team interfaces with threat intelligence customers, managing educational presentations and incorporating feedback into threat intelligence capability development.

  • Lead the development of routine and ad hoc threat intelligence written products, and own the customer dissemination portfolio for the team.

  • Consume and curate threat data to create intelligence assessments in support of our incident response, threat hunting, threat detection, security engineering, and risk prioritization missions.

  • Consume and curate OSINT and paid-for vendor reporting to contextualize the threat landscape.

  • Write scripts (or capability to learn how to) and tools to help with analysis and build automation to aid investigations and threat research using lessons learned.

  • Build expertise on any threats targeting Salesforce and provide attribution to attacker activity when possible

  • Identify new and existing threats and clearly distill this information to support finished intelligence to multiple internal partners, including executives.

  • Perform intelligence research during incident response, supporting multiple teams and drive direction of investigations based on knowledge of attackers.

You're Our Person If You Have:

  • At least 5 years of professional experience identifying patterns and trends across various data sources to distill findings concisely for various audiences at scale.

  • 3+ years experience with Cyber Threat Intelligence writing for both technical, non-technical, and executive audiences - ideally with threat briefings, threat reports, blog posts, or similar finished intelligence.

  • 3+ years experience conducting and correlating threat research using OSINT, paid-for threat vendors, incident response engagement data, and proprietary tools.

  • A capable oral and written communicator, you are able to engage others in the business at multiple levels to translate threat research into actionable recommendations to shape the business.

  • Experience identifying, tracking of advanced cyber threat actors, including government-backed and advanced e-crime adversaries; knowledge of advanced actor TTPs and how to translate these to various audiences.

  • Established threat intelligence practitioner (active engagement in the Information Security or Threat Community with contacts is a big plus).

  • Experience using various AI tools for large data set analysis and intelligence support.

  • You operate in a semi-autonomous to autonomous manner, driving the delivery of projects and deliverables with minimal oversight across multiple teams.

  • You can work actively as a part of a globally distributed team, including remote and in-person colleagues.

Even Better If You Have:

  • 5 years hands-on experience with strategic intelligence writing and standard conventions (BLUF, Diamond Model, MITRE ATT&CK), with a proven track record of authoring dozens of research articles and public-facing blog posts.

  • Capability to learn or experience with security analysis tools (Jupyter notebooks, Splunk, ElasticSearch, etc.).

  • Experience with SOAR platforms.

  • Experience with various AI tools.

  • Experience with threats in AWS, Microsoft Azure, and Google Cloud.

  • Experience or an understanding of hunting/IR tools used for host and network analysis.

  • Experience using Threat Intelligence Platforms; building integrations with these platforms is a plus.

  • You have an understanding of existing and emerging threats to an organization spanning multiple industries and threat profiles; any threat hunting experience is a big plus.

  • Active member of private, invite-only Information Security trust groups with extensive industry and community contacts.

  • You have performed all of the above “at scale“ in a large, complex environment

This candidate must be a U.S. citizen (U.S. born or naturalized) who does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.

Unleash Your Potential

When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.

Accommodations

If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.

Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.

Posting Statement

Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $148,500 - $223,900 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

Skills Required

  • At least 5 years of professional experience identifying patterns and trends across multiple data sources and distilling findings for varied audiences
  • At least 3 years of experience writing cyber threat intelligence for technical, non-technical, and executive audiences
  • At least 3 years of experience conducting and correlating threat research using OSINT, paid threat vendors, incident response data, and proprietary tools
  • Strong oral and written communication skills, including translating threat research into actionable business recommendations
  • Experience identifying and tracking advanced cyber threat actors, including government-backed and advanced e-crime adversaries
  • Established threat intelligence practitioner with active information security or threat community engagement
  • Experience using AI tools for large dataset analysis and intelligence support
  • Ability to work autonomously across multiple teams and collaborate in a globally distributed environment
  • U.S. citizenship, including U.S.-born or naturalized status
  • Must not hold dual citizenship
  • Ability to meet customer and government screening standards and complete a U.S. federal government Minimum Background Investigation for Moderate Public Trust
  • Hands-on experience with strategic intelligence writing and conventions including BLUF, Diamond Model, and MITRE ATT&CK
  • Experience authoring research articles and public-facing blog posts
  • Experience with Jupyter notebooks, Splunk, or Elasticsearch
  • Experience with SOAR platforms
  • Experience with threats in AWS, Microsoft Azure, and Google Cloud
  • Experience with host and network hunting or incident response analysis tools
  • Experience using Threat Intelligence Platforms, including building integrations
  • Threat hunting experience
  • Membership in private information security trust groups and extensive industry contacts
  • Experience delivering threat intelligence at scale in a large, complex environment

Salesforce Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Salesforce and has not been reviewed or approved by Salesforce.

  • Fair & Transparent Compensation Pay is positioned as above-market in the U.S., with multiple peer-reported benchmarks converging around a similar median total compensation figure. Compensation is also framed as broadly viewed as fair in aggregate, even while acknowledging variation by role and group.
  • Parental & Family Support Parental leave is described as notably generous for U.S. caregivers, with additional supports like gradual return-to-work and doula reimbursement. Family-building programs are also emphasized through fertility/adoption/surrogacy support with sizeable reimbursement limits.
  • Wellbeing & Lifestyle Benefits Mental-health and coaching offerings are highlighted as accessible supports alongside financial-wellbeing tools. Volunteer Time Off and donation matching are presented as distinctive lifestyle-aligned benefits that add value beyond cash compensation.

Salesforce Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
72,000 Employees

What We Do

Salesforce is the #1 AI CRM, where Humans with agents drive customer success together. Through Agentforce, our groundbreaking suite of customizable agents and tools, Salesforce brings autonomous AI agents, unified data from any source, and best-in-class Customer 360 apps together on one integrated platform to help companies connect with customers in a whole new way. Salesforce is democratizing AI agents for businesses of every size and industry so every company can embrace a workforce without limits. Our low code, open, and secure platform helps companies build and customize Salesforce fast so they can safely scale AI-powered work to every customer and employee experience and transform their business. Salesforce is proud to be the market leader, but we’re even more proud to lead in philanthropy, innovation and culture. Guided by core values of trust, customer success, innovation, equality, and sustainability, Salesforce is more than a business — we’re a platform for change.

Why Work With Us

There’s no typical day in the life of a Salesforce employee. You could be transforming our next AI innovation — or transforming your community. Closing deals — or closing your laptop for a day of Volunteer Time Off. Driving change for our customers — or driving change within one of our high-performing teams.

Gallery

Gallery

Similar Jobs

Sprout Social Logo Sprout Social

Customer Success Manager

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
92K-153K Annually

CrowdStrike Logo CrowdStrike

Systems Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
100K-145K Annually

CrowdStrike Logo CrowdStrike

Engineer III, Hardware Development (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

HiBob Logo HiBob

Sales Engineer

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
108K-145K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account