Description
We are looking for curious individuals who are dedicated to identifying abusers who commit fraud and/or leverage our services to make the Internet a hostile space. You are the right person for this job if you understand spamming, malicious websites, phishing, and a plethora of other inappropriate ways that Internet Threat Actors will take advantage. You don’t want to play whack-a-mole; you want to automate tedious work away and break bad actors' business models. You are completely comfortable using Splunk for investigations, and know that progress itself is more important than perfection. We are looking for our next team member to join us in this fast-paced environment at Salesforce.
At our core, the Platform Defense and Safety team works to detect and respond to malicious user activity (misuse, abuse, crime, etc) when everything is working “as designed”. At any moment in time, multiple actors are attempting to bypass detection and response systems, masquerading as customers in order to take unfair advantage of our systems and services. Different from the full compromise scenarios we know and love, abuse is a slow simmering burn, where some of our users can become a problem.
Responsibilities
Abuse Detection and Response: Review, triage, investigate, and respond to abuse reports and detections impacting Salesforce products, such as Sales Cloud and Marketing Cloud.
Cross-Functional Partnership: Work collaboratively with Salesforce product teams to manage third-party report escalations, and across diverse teams to achieve organizational goals.
Threat Analysis: Maintain a deep understanding of threats and threat actors in the online abuse landscape, particularly those exploiting systems as designed.
Innovation in Abuse Mitigation: Identify, articulate, and document opportunities for innovation in platform abuse detection, mitigation, and response tooling.
Stay Informed on Cyber Crime Trends: Continuously monitor emerging trends in cyber crime and online fraud.
Documentation and Playbooks: Contribute to the development and maintenance of team playbooks and documentation.
Crisis Management: Demonstrate the ability to take thoughtful and deliberate action in stressful crisis situations.
Represent Anti-Abuse Efforts: Act as a public face of anti-abuse initiatives at Salesforce.
Requirement
5+ years demonstrated working experience in the following Information Security domains: product/platform abuse, threat intelligence, incident response, trust and safety, and/or threat detection
Alternatively, experience in a customer-facing technical support role interacting with any of the above
Expertise in Product Abuse detection, mitigation, and response
Demonstrated working experience writing documentation, such as team runbooks
Experience leveraging Open Source Intelligence (OSINT) and commercial security tools to support investigations
Proficient in email header analysis to investigate reports of email spam and phishing
Proficient using Splunk for investigations and to create detections/dashboards
Proficient with Python, especially demonstrated experience using Python notebooks
Experience building Security Orchestration and Response (SOAR) Playbooks
Experience analyzing large and complex data sets
Experience using various Salesforce products
Proficient using Version Control Systems, and GitHub