> Markdown version of [/jobs/ext/2120399-senior-lead-incident-responder](https://www.wearedevelopers.com/jobs/ext/2120399-senior-lead-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Lead Incident Responder - **Company:** Salesforce.com, Inc. - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $172,500.0 - $260,100.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Big Data, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Log Analysis, OAuth, PCI Data Security Standards, Performance Tuning, Regular Expressions, Salesforce.Com, SQL Databases, Google Cloud, Cyber Threat Analysis, Splunk, Marketing Cloud - **Published:** August 19, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88077291/1 ## About the Role * 8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating. * Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification. * Expert log analysis - Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation - performed independently, fast, without assistance. * Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents. * Deep technical knowledge in systems, networks, cloud security, and forensic techniques. * Demonstrated composure and judgment across multiple concurrent high-pressure investigations. * Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms. * Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently. * Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA). * Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes. Even Better If You Have: * Salesforce Admin certified. * 3-5 years in a lead or senior IR role within a large, global organization. * Experience with complex forensic cases involving large datasets or unusual/novel data sources - the harder the data, the better. * Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows). * Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent). * Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure). * Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns. ## Description * Own the analytical hardest-part of major investigations - take large, messy, multi-source datasets (Splunk, SQL, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk. * Serve as the team's go-to analyst on complex or ambiguous cases - the person others bring a stalled investigation to when the data isn't giving up its answer easily. * Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure. * Build accurate, complete, and defensible investigation timelines and CAN reports - analysis that holds up to legal and regulatory scrutiny. * Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud - ATO, credential compromise, data exfiltration, API abuse, connected app exploitation. * Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination. * Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly. * Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering. * Raise the analytical bar on the team - review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique. * Support CREST's AI-first initiatives - use and help improve automated agents for triage, documentation, and investigation workflows. * Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Promotion Interview Questions: How to Answer and Get the Job](https://www.wearedevelopers.com/magazine/413-promotion-interview-questions-how-to-answer-and-get-the-job)