Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Lead Incident Responder

$172.5k - $260.1k

Salesforce

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.The Experience:This is CREST's analysis anchor. The primary job is investigation — but specifically the hard analytical core of it: taking a messy, high-volume, multi-source pile of log data and figuring out what actually happened, what the threat actor touched, and what was truly at risk. We're hiring for analytical horsepower first. The right person is someone who is genuinely a killer in analysis — they see the pattern in the noise faster than anyone in the room, build a defensible timeline from incomplete evidence, and can prove what happened rather than guess at it. Operational coordination and customer work are part of the role, but they sit on top of a foundation of elite investigative analysis. If you're an investigator who runs to the data, this role is built for you.What You'll Actually Be Doing:Own the analytical hardest-part of major investigations — take large, messy, multi-source datasets (Splunk, SQL, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk.Serve as the team's go-to analyst on complex or ambiguous cases — the person others bring a stalled investigation to when the data isn't giving up its answer easily.Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure.Build accurate, complete, and defensible investigation timelines and CAN reports — analysis that holds up to legal and regulatory scrutiny.Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud — ATO, credential compromise, data exfiltration, API abuse, connected app exploitation.Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination.Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly.Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering.Raise the analytical bar on the team — review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique.Support CREST's AI-first initiatives — use and help improve automated agents for triage, documentation, and investigation workflows.Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives.You're Our Person If You Have:8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating.Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification.Expert log analysis — Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation — performed independently, fast, without assistance.Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.Deep technical knowledge in systems, networks, cloud security, and forensic techniques.Demonstrated composure and judgment across multiple concurrent high-pressure investigations.Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms.Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes.Even Better If You Have:Salesforce Admin certified.3–5 years in a lead or senior IR role within a large, global organization.Experience with complex forensic cases involving large datasets or unusual/novel data sources — the harder the data, the better.Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows).Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent).Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure).Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns.Unleash Your PotentialWhen you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.AccommodationsIf you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.Posting StatementSalesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $172,500 - $260,100 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.SummaryLocation: Washington - SeattleType: Full time

Vacancy posted 19 days ago
Similar jobs that could be interesting for youBased on the Senior Lead Incident Responder in Washington DC vacancy
  • $172.5k - $260.1k

     ...up your career at the company leading workforce transformation in...  ...into advanced or high-impact incidents across Salesforce Core, Marketing...  ...rigor, and mentor junior responders on advanced analysis technique...  ...certified.3-5 years in a lead or senior IR role within a large,... 
    Senior
    Full time

    Salesforce

    Washington DC
    4 days ago
  •  ...Description Job Description Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client...  ...experience and 4 years' experience in IT Solutions at senior management ~ Certified Information Systems Security Professional... 
    Suggested
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    6 days ago
  •  ...DC Position Overview: We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and...  ...relevant technical experience or 4 years in IT solutions at a senior management level. At least 10 years of experience in an... 
    Suggested
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions, LLC

    Washington DC
    6 days ago
  • G2IT, LLC. is seeking an experienced Incident Responder to join a mission-focused cyber defense team supporting the Office of Naval Intelligence (ONI) at HGCC in Suitland, MD. You will act as a digital first responder to defend maritime intelligence networks and investigate... 
    Senior
    Work at office

    G2IT LLC

    Suitland, MD
    1 day ago
  • Leidos is seeking a Security Operations Center (SOC) Lead in Alexandria, VA, to direct day-to-day SOC activities and manage 24x7 incident response operations for the DISA GSM-O program. The role requires a TS/SCI clearance, a strong background in cybersecurity, and hands... 
    Senior

    Leidos Inc

    Alexandria, VA
    6 days ago
  • Base One Technologies is seeking a seasoned Cyber Threat Hunter to serve as the hunt and incident response SME in a high-security environment. You will apply in-depth knowledge of threat actor tools and TTPs, distill findings into executive summaries and deep technical... 
    Senior

    Base One Technologies

    Arlington, VA
    5 days ago
  • Leidos is seeking a Security Operations Center Lead for the DISA GSM-O program in Alexandria, VA. The role directs day-to-day SOC activities, coordinates 24x7 incident handling, and ensures strict adherence to incident response processes. Qualified candidates will have... 
    Senior

    Via Logic LLC

    Alexandria, VA
    4 days ago
  • A dynamic Woman Owned Small Business is seeking a Senior Incident Response Coordinator for their Program Management and Cyber Support Services project in Arlington, Virginia. The role entails coordinating cyber incident responses, managing stakeholder communications, and... 
    Senior

    Zantech

    Arlington, VA
    6 days ago
  • $148.5k - $223.9k

     ...level-up your career at the company leading workforce transformation in the agentic...  ...'s Computer Security Incident Response Team (CSIRT) provides 24x7x3...  ...customer data from adversaries.As a Senior Incident Responder, you'll be a core member of the response... 
    Senior
    Full time
    Monday to Friday
    Night shift

    Salesforce

    Washington DC
    2 days ago
  • ID.me is seeking a highly experienced SOC Lead to play a pivotal role in our advanced security operations. Based in McLean, VA, you will manage complex incidents, mentor junior analysts, and drive strategic SOC initiatives across cloud-native environments. You will lead... 
    Senior

    ID.me Inc

    Mc Lean, VA
    3 days ago
  • $101k - $125k

     ...relationship to the Director Projects – Health, Safety, the Senior Lead, Occupational Health & Safety, Projects is responsible...  ...and measures. Ensures available resources to respond to critical workplace incidents, personally leads investigations into significant events... 
    Senior
    Full time
    For contractors
    Local area
    Flexible hours

    Teck

    Washington DC
    more than 2 months ago
  •  ...Description Job Description Alternate Lead Senior Information Systems Security Officer...  ...vulnerability management, POA&M, change management, incident coordination, audit support, or...  ...evidence for assigned systems. Respond to evidence requests within required timelines... 
    Senior
    Full time
    Contract work
    Immediate start
    Remote work
    2 days per week

    R3 Management Services

    Washington DC
    5 days ago
  • $138k - $209k

     ...that matter, alongside industry‑leading experts, in an environment...  ...unique needs of our client as an Incident Management Lead. Project...  ...identifying, analyzing, and responding to cybersecurity threats. This...  ...investigations, collaborate with senior leadership on threat... 
    Contract work
    Temporary work

    AIS (Applied Information Sciences)

    Alexandria, VA
    5 days ago
  •  ...Resilience team is looking to hire an Incident / Crisis Management Lead to help drive the continuous...  ...operational resilience and can effectively respond and mitigate any potential incidents...  ...Act as a trusted advisor to senior leadership during crisis events, providing... 
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    WTW inc.

    Arlington, VA
    3 days ago
  •  ...Allen Hamilton is seeking an experienced information security risk specialist to join a 24x7 SOC and Incident Response team. You will monitor, detect, investigate, and respond to cybersecurity threats across enterprise networks, endpoints, and applications, leveraging SIEM... 
    Senior

    Booz Allen Hamilton

    Bethesda, MD
    2 days ago
  •  ...requires U.S. citizenship and an active Top Secret clearance. You will lead auditing efforts in eMASS, manage compliance tasks, and support...  ...include vulnerability assessments, security audits, incident response support, and delivering cybersecurity #J-18808-Ljbffr... 
    Senior

    Po'okela

    Arlington, VA
    1 day ago
  •  ...and DoD cybersecurity compliance, vulnerability analysis, and incident response support. Applicants must hold U.S. citizenship, a Top...  ...3 / DCWF certifications. Bachelor’s in CS with 4-7 years in a lead/senior role is required, with strong eMASS experience #J-18808-Ljbffr... 
    Senior

    International Executive Service Corps

    Arlington, VA
    5 days ago
  • General Dynamics - IT is seeking an IT Network Security Team Lead to guide a security engineering team in Bethesda, MD. You will oversee...  .... Responsibilities include architectural design, risk reviews, incident escalation, and alignment with HHS/NID directives. Leadership... 
    Senior
    3 days per week

    General Dynamics - IT

    Bethesda, MD
    1 day ago
  •  ...to Obtain Public TrustWhat You Will Do:The Fraud Analytics Senior Consultant Lead will support highly specialized fraud analytics activities...  ...on predictive analytics, deep forensics, fraud detection, incident support, data integration, and continuous enhancement of analytics... 
    Senior
    Full time
    For contractors
    Flexible hours

    Guidehouse

    Arlington, VA
    2 days ago
  • $131.3k - $237.35k

     ...through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The...  ...program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise... 
    Senior
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    5 hours ago
  • $86.8k - $198k

    Incident Response Analyst, SeniorThe Opportunity:Respond to cybersecurity incidents and proactively prevent the reoccurrence of these incidents. Apply specific functional knowledge to resolve cybersecurity incidents. Analyze or contribute to solutions to a variety of problems... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    10 hours ago
  • $155k - $200k

     ...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is...  ...response for cybersecurity and data privacy incidentsTaking lead responsibility in responding to clients and carriers, and overseeing breach... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    Wilson Elser

    Washington DC
    1 day ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    4 days ago
  •  ...team! Zantech is looking for a talented Senior Incident Response Coordinator to contribute to...  ...Response Coordinator serves as the lead for incident management and coordination...  ...private sector partners to prepare for, respond to, and recover from significant cyber incidents... 
    Senior
    Contract work
    Local area

    Zantech

    Arlington, VA
    2 days ago
  • $86.8k - $198k

    Incident Response Analyst, SeniorThe Opportunity: You will serve as a key member of a 24x7x365 Security Operations Center and Incident...  ...investigation, and incident responseExperience analyzing and responding to security events across enterprise networks, endpoints, applications... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    4 days ago
  • $50 per hour

     ...someone who is a motivator, innovator, and change agent.Our Lead Senior Tax Accountant in the State Tax Compliance function will oversee...  ...workflow.-Oversees and assist with gathering information and responding to state tax notices received from the state/local tax... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Casual work
    Work at office
    Local area
    Flexible hours

    Lockheed Martin

    Bethesda, MD
    2 days ago
  • $100k - $158k

     ...a collaborative environment? As an experienced Oracle Payroll Lead -Senior Consultant, you will have the ability to share new ideas and collaborate...  ...support for Oracle HCM Cloud (e.g., Benefits, Payroll ).* Own incident management: triage, prioritization, stakeholder communication,... 
    Senior
    Flexible hours

    Deloitte

    Rosslyn, VA
    10 hours ago
  •  ...for commercial and government clients, is seeking a full-time Lead Senior Information Systems Security Officer (ISSO)  to support the...  ...configuration, and compliance data to support risk-based decision-making, incident response coordination, continuous monitoring, and overall... 
    Senior
    Full time
    Contract work
    For contractors
    Remote work
    2 days per week

    Dynamic Solutions Technology LLC

    Washington DC
    6 days ago
  •  ...Job Description Job Description Lead Senior Information Systems Security Officer Position Summary The Lead Senior Information...  ...monitoring activities within required timelines. Provide ISSO-level incident response coordination, including affected-system context,... 
    Senior
    Full time
    Contract work
    For contractors
    Remote work
    Monday to Friday
    2 days per week

    R3 Management Services

    Washington DC
    5 days ago
  • $147k

     ...employees. Responsibilities Position Overview As the OMC Senior Systems Administrator (Lead), you will act as a model of customer service excellence...  ...IT leadership and JSP to resolve complex infrastructure incidents; independently determines escalation paths and... 
    Senior
    Contract work
    For contractors
    Work at office

    Empower AI Inc.

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Lead Incident Responder. Be the first to apply!