Senior Lead Incident Responder

Salesforce

Washington

On-site

USD 180,000 - 250,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Salesforce is seeking an experienced security incident responder to own high‑impact investigations. You will analyze large, multi‑source data sets, reconstruct attacker activity, and determine what was touched and at risk.

You will lead complex cases, coordinate containment actions, and communicate findings to legal and executive teams. You will work with Threat Intelligence, Detection Engineering, and Legal to improve detection coverage and incident response workflows, mentoring junior

Qualifications

  • 8+ years in security incident response with hands-on investigations
  • Expert log analysis—Splunk/SQL with multi-source joins and regex parsing
  • Experience handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation

Responsibilities

  • Own the analytical hardest part of major investigations: reconstruct multi-source activity and risk.
  • Serve as the go-to analyst for complex, ambiguous cases.
  • Perform expert log analysis: complex joins, regex parsing, and hypothesis-driven pivoting.
  • Build accurate investigation timelines and defensive CAN reports for legal/regulatory scrutiny.
  • Lead investigations into high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud.
  • Coordinate containment actions with stakeholders and leadership.
  • Lead customer calls with legal/regulatory pressure and communicate findings clearly.

Skills

IR experience
Advanced log analysis
Splunk
SQL
Threat hunting
Forensic techniques
Stakeholder comms
Leadership

Tools

Splunk
SQL
Regex parsing
Data correlation

Job description

Job Category

Enterprise Technology & Infrastructure

Job Details
About Salesforce

Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.

Ready to level-up your career at the company leading workforce transformation in the agentic era? You're in the right place! Agentforce is the future of AI, and you are the future of Salesforce.

The Experience

This is CREST's analysis anchor. The primary job is investigation - but specifically the hard analytical core of it: taking a messy, high-volume, multi-source pile of log data and figuring out what actually happened, what the threat actor touched, and what was truly at risk. We're hiring for analytical horsepower first. The right person is someone who is genuinely a killer in analysis - they see the pattern in the noise faster than anyone in the room, build a defensible timeline from incomplete evidence, and can prove what happened rather than guess at it. Operational coordination and customer work are part of the role, but they sit on top of a foundation of elite investigative analysis. If you're an investigator who runs to the data, this role is built for you.

What You'll Actually Be Doing
  • Own the analytical hardest-part of major investigations - take large, messy, multi-source datasets (Splunk, SQL, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk.
  • Serve as the team's go-to analyst on complex or ambiguous cases - the person others bring a stalled investigation to when the data isn't giving up its answer easily.
  • Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure.
  • Build accurate, complete, and defensible investigation timelines and CAN reports - analysis that holds up to legal and regulatory scrutiny.
  • Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud - ATO, credential compromise, data exfiltration, API abuse, connected app exploitation.
  • Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination.
  • Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly.
  • Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering.
  • Raise the analytical bar on the team - review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique.
  • Support CREST's AI-first initiatives - use and help improve automated agents for triage, documentation, and investigation workflows.
  • Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives.
You're Our Person If You Have
  • 8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating.
  • Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification.
  • Expert log analysis - Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation - performed independently, fast, without assistance.
  • Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.
  • Deep technical knowledge in systems, networks, cloud security, and forensic techniques.
  • Demonstrated composure and judgment across multiple concurrent high-pressure investigations.
  • Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms.
  • Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.
  • Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).
  • Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes.
Even Better If You Have
  • Salesforce Admin certified.
  • 3-5 years in a lead or senior IR role within a large, global organization.
  • Experience with complex forensic cases involving large datasets or unusual/novel data sources - the har
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Salesforce • Virginia (MN)

On-site
USD 150,000 - 190,000
Senior Lead Incident Responder
Senior Lead Incident Responder

Socket.dev • Seattle (WA)

On-site
USD 173,000 - 260,000
Lead, Incident Response - Global CSIRT
Lead, Incident Response - Global CSIRT

Salesforce • Virginia (MN)

On-site
USD 140,000 - 190,000
Senior Platform Trust and Safety Engineer
Senior Platform Trust and Safety Engineer

Salesforce • Washington

On-site
USD 130,000 - 170,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • McLean (VA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

salesforce.com, inc. • Bellevue (WA)

On-site
USD 149,000 - 224,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Socket.dev • McLean (VA)

On-site
USD 149,000 - 224,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Salesforce, Inc. • United States

On-site
USD 173,000 - 260,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Salesforce, Inc. • Bellevue (WA), Northern (KY)

Hybrid
USD 149,000 - 224,000
Senior Lead Incident Responder
Senior Lead Incident Responder

Salesforce • Seattle (WA)

On-site
USD 173,000 - 260,000