Lead, Incident Response

Salesforce

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Mclean, VA
Salary
$172,500–$260,100 / yr
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $173k
This role $216k
$112k most similar roles pay here $276k

This role pays more than 82% of similar roles. Most pay $142,337–$203,925 — the shaded band above. At the midpoint, this role pays about $216k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 106 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 98 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Lead, Incident Response

Lead, Incident Response – Global CSIRT joins the Computer Security Incident Response Team to serve as a senior technical escalation point and lead end-to-end responses to high-severity incidents. This hands-on role involves investigating sophisticated adversaries, insider threats, and web application attacks across on-premises and multi-cloud environments including AWS, Azure, and GCP. The successful candidate will build process improvements, playbooks, and automation using SOAR tooling and detection-as-code to improve response times. Key responsibilities include performing host and network forensics across Windows, macOS, and Linux systems while analyzing file system, memory, and network artifacts for indicators of compromise. Required expertise includes a deep understanding of the threat landscape, TTPs, and MITRE ATT&CK frameworks. The role focuses on protecting company and customer data from adversaries through proactive detection engineering and technical leadership within a 24x7x365 security operations environment.

What you'll do

  • Lead end-to-end response for high-severity incidents from initial triage through containment, eradication, and recovery.
  • Serve as the senior technical escalation point and primary decision-maker during active security incidents.
  • Investigate sophisticated adversaries, insider threats, and web application attacks across multi-cloud and on-premises environments.
  • Design and build automated playbooks and SOAR tooling to reduce time-to-detect and time-to-respond.
  • Develop detection-as-code and other technical improvements to enhance overall security capabilities.
  • Mentor junior responders to develop their skills and grow into advanced incident response roles.

What we're looking for

  • You must have at least 8 years of experience in information security with hands-on incident response and monitoring.
  • You must perform host and network forensics across Windows, macOS, and Linux systems.
  • You must have experience responding to incidents in cloud environments including AWS, Azure, or GCP.
  • You must possess a deep understanding of the threat landscape, TTPs, and system/network hardening best practices.
  • Experience with SOAR tooling, scripting, and detection-as-code is preferred for capability uplift.
  • Relevant certifications such as SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or OSCP are preferred.
  • You must be a U.S. citizen (born or naturalized) who does not hold dual citizenship.
  • You must be able to pass a U.S. federal government Minimum Background Investigation for a Moderate Public Trust position.

More like this

Similar roles

Senior Incident Responder, Global CSIRT

Salesforce

Remote (Mclean, VA) 7 days ago $148,500$223,900
Incident Response SOAR CI/CD AWS Azure GCP Windows macOS Linux Malware Analysis Detection Engineering Forensics AI LLM Salesforce Platform SaaS
5+ yrs exp Remote

Principal Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Senior Lead Incident Responder

Salesforce

Remote (Seattle, WA) 24 days ago $172,500$260,100
Splunk SQL Regex API Salesforce Marketing Cloud Commerce Cloud AWS GCP Azure Detection Engineering Incident Response SaaS GDPR PCI-DSS DORA
8+ yrs exp Remote

Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Lead Detection Engineer, Cyber Defense & Response

Prudential Financial

Newark, NJ 57 days ago $123,700$204,100
Splunk Enterprise Security SPL KQL Python SOAR CI/CD MITRE ATT&CK Cyber Kill Chain Threat Hunting Incident Response Digital Forensics Security Automation Linux Windows macOS