Senior Lead Incident Responder

Salesforce

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Seattle, WA
Salary
$172,500–$260,100 / yr
Posted
24 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $180k
This role $216k
$127k most similar roles pay here $274k

This role pays more than 76% of similar roles. Most pay $144,386–$216,262 — the shaded band above. At the midpoint, this role pays about $216k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About Salesforce

Salesforce is the world''s leading customer relationship management (CRM) platform, offering cloud-based software for sales, service, marketing, analytics, and application development. Industry: Enterprise Software & Cloud Computing

Salesforce currently has 106 open roles on FindRole.

Listed pay typically runs $148,500–$260,100 across 98 roles with salary data.

Most-posted roles

View all roles at Salesforce

At a glance

TL;DR · Senior Lead Incident Responder

Senior Lead Incident Responder The Senior Lead Incident Responder joins the CREST team to serve as a primary analytical anchor for complex security investigations. This role focuses on the core investigation of high-volume, multi-source log data to reconstruct threat actor activities and determine what was at risk. You will perform expert log analysis using Splunk, SQL, and regex parsing to build defensible timelines and reports that withstand legal scrutiny. Key responsibilities include managing incidents involving account takeover, credential compromise, and API abuse across Salesforce Core, Marketing Cloud, and Commerce Cloud platforms. You will also execute containment actions, lead high-pressure customer calls with legal counsel, and engineer new detections for identified TTPs. Required skills include deep knowledge of cloud security, forensic techniques, and familiarity with global compliance standards like GDPR and PCI-DSS to resolve critical security threats.

What you'll do

  • Analyze large, multi-source datasets from Splunk, SQL, and APIs to reconstruct threat actor activities and identify what was at risk.
  • Perform complex log analysis using regex parsing, custom correlation, and hypothesis-driven pivoting under time pressure.
  • Build defensible investigation timelines and CAN reports that meet legal and regulatory scrutiny.
  • Lead investigations into high-impact incidents including account takeovers, data exfiltration, and API abuse across Salesforce platforms.
  • Execute strategic containment actions such as credential rotations, IP blocks, and OAuth revocations.
  • Lead technical calls with customers and legal counsel to communicate complex findings clearly.
  • Engineer new detections for identified TTPs by collaborating with the Detection Engineering team.
  • Mentor junior responders and provide structured feedback on investigation quality and analytical rigor.

What we're looking for

  • 8+ years of experience in security incident response with consistent hands-on technical case work.
  • Demonstrated ability to independently analyze large, multi-source datasets to produce defensible investigation accounts.
  • Expert log analysis skills using Splunk and SQL, including complex joins, regex parsing, and custom correlation.
  • Expertise handling account takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation.
  • Deep technical knowledge in systems, networks, cloud security, and forensic techniques.
  • Strong familiarity with Salesforce products or comparable multi-tenant SaaS platforms.
  • Ability to lead customer calls and communicate complex technical findings clearly to non-technical audiences.
  • Knowledge of global compliance standards such as GDPR, PCI-DSS, and DORA.
  • Salesforce Admin certification (preferred).
  • 3–5 years in a lead or senior IR role within a large, global organization (preferred).
  • Experience with complex forensic cases involving large datasets or unusual data sources (preferred).
  • Hands-on experience with AI/automation tooling in security operations (preferred).
  • Advanced certifications such as SANS GCFA, GNFA, GCIH, OSCP, or equivalent (preferred).
  • Experience with e-commerce security or cloud-native environments like AWS, GCP, or Azure (preferred).

More like this

Similar roles

Senior Incident Responder, Global CSIRT

Salesforce

Remote (Mclean, VA) 7 days ago $148,500$223,900
Incident Response SOAR CI/CD AWS Azure GCP Windows macOS Linux Malware Analysis Detection Engineering Forensics AI LLM Salesforce Platform SaaS
5+ yrs exp Remote

Lead, Incident Response

Salesforce

Remote (Mclean, VA) 7 days ago $172,500$260,100
Incident Response SOAR Detection-as-Code AWS Azure GCP CI/CD Network Forensics Malware Analysis Detection Engineering MITRE ATT&CK Linux Windows macOS Security Orchestration
8+ yrs exp Remote

Senior Incident Handler

Allstate

Remote (IL) 59 days ago $120,000$193,725
Incident Response EDR XDR SIEM Python PowerShell SOAR Malware Analysis Forensic Analysis Threat Hunting Network Security AI Scripting Cybersecurity Operations
5+ yrs exp Remote

Principal Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Senior Principal System Safety Specialist

General Dynamics

Huntsville, AL 7 days ago $112,840$138,000
System Safety Engineering Risk Management Mil-std-882E AR385-10 Systems Engineering Technical Analysis Excel Word PowerPoint Rotary Wing Aviation Aerodynamics Propulsion
10+ yrs exp Hybrid