Senior Lead Incident Responder

Salesforce.com, Inc.
Seattle, WA, United States
18 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$172,500.0 - $260,100.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Big Data Software as a Service Cloud Computing Cloud Computing Security Cyber Security Intrusion Detection and Prevention Log Analysis OAuth
+9 more
PCI Data Security Standards Performance Tuning Regular Expressions Salesforce.Com SQL Databases Google Cloud Cyber Threat Analysis Splunk Marketing Cloud

Job description

  • Own the analytical hardest-part of major investigations - take large, messy, multi-source datasets (Splunk, SQL, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk.
  • Serve as the team’s go-to analyst on complex or ambiguous cases - the person others bring a stalled investigation to when the data isn’t giving up its answer easily.
  • Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure.
  • Build accurate, complete, and defensible investigation timelines and CAN reports - analysis that holds up to legal and regulatory scrutiny.
  • Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud - ATO, credential compromise, data exfiltration, API abuse, connected app exploitation.
  • Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination.
  • Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly.
  • Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering.
  • Raise the analytical bar on the team - review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique.
  • Support CREST’s AI-first initiatives - use and help improve automated agents for triage, documentation, and investigation workflows.
  • Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives.

Requirements

  • 8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating.
  • Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification.
  • Expert log analysis - Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation - performed independently, fast, without assistance.
  • Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.
  • Deep technical knowledge in systems, networks, cloud security, and forensic techniques.
  • Demonstrated composure and judgment across multiple concurrent high-pressure investigations.
  • Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms.
  • Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.
  • Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).
  • Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes.

Even Better If You Have:

  • Salesforce Admin certified.
  • 3-5 years in a lead or senior IR role within a large, global organization.
  • Experience with complex forensic cases involving large datasets or unusual/novel data sources - the harder the data, the better.
  • Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows).
  • Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent).
  • Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure).
  • Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns.

Benefits & conditions

benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.

In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: https://www.salesforcebenefits.com.

At Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $172,500 - $260,100 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.

About the company

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword - it’s a way of life. The world of work as we know it is changing and we’re looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce’s core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce., Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:10 min

Why organizations combine big data and machine learning

Ayon Roy · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all