Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Lead Incident Responder

$172.5k - $260.1k

Salesforce

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.The Experience:This is CREST's analysis anchor. The primary job is investigation — but specifically the hard analytical core of it: taking a messy, high-volume, multi-source pile of log data and figuring out what actually happened, what the threat actor touched, and what was truly at risk. We're hiring for analytical horsepower first. The right person is someone who is genuinely a killer in analysis — they see the pattern in the noise faster than anyone in the room, build a defensible timeline from incomplete evidence, and can prove what happened rather than guess at it. Operational coordination and customer work are part of the role, but they sit on top of a foundation of elite investigative analysis. If you're an investigator who runs to the data, this role is built for you.What You'll Actually Be Doing:Own the analytical hardest-part of major investigations — take large, messy, multi-source datasets (Splunk, SQL, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk.Serve as the team's go-to analyst on complex or ambiguous cases — the person others bring a stalled investigation to when the data isn't giving up its answer easily.Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure.Build accurate, complete, and defensible investigation timelines and CAN reports — analysis that holds up to legal and regulatory scrutiny.Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud — ATO, credential compromise, data exfiltration, API abuse, connected app exploitation.Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination.Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly.Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering.Raise the analytical bar on the team — review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique.Support CREST's AI-first initiatives — use and help improve automated agents for triage, documentation, and investigation workflows.Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives.You're Our Person If You Have:8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating.Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification.Expert log analysis — Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation — performed independently, fast, without assistance.Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.Deep technical knowledge in systems, networks, cloud security, and forensic techniques.Demonstrated composure and judgment across multiple concurrent high-pressure investigations.Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms.Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes.Even Better If You Have:Salesforce Admin certified.3–5 years in a lead or senior IR role within a large, global organization.Experience with complex forensic cases involving large datasets or unusual/novel data sources — the harder the data, the better.Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows).Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent).Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure).Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns.Unleash Your PotentialWhen you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best, and our AI agents accelerate your impact so you can do your best. Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.AccommodationsIf you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form.Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.Posting StatementSalesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $172,500 - $260,100 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.SummaryLocation: Washington - SeattleType: Full time

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Lead Incident Responder in Seattle, WA vacancy
  •  ...leader in defense technology based in the United States, is seeking a Senior SecOps Analyst to oversee security operations on the Detection and Response team. You will triage alerts, respond to incidents across endpoints, cloud, and SaaS, and mentor junior analysts while... 
    Senior

    Anduril Industries

    Seattle, WA
    9 hours ago
  •  ...la résolution des pannes Avaya et MS Teams, avec escalade coordonnée et communication fluide entre les groupes. Vous gérerez les incidents, documenterez les procédures et contribuerez à l’amélioration continue des systèmes de communication d’entreprise, tout en respectant... 
    Senior

    General Dynamics

    Seattle, WA
    3 days ago
  • Anduril Industries is seeking a Senior SecOps Analyst to join our Detection and Response team. You will monitor and respond to adversarial activity, integrating detections with...  ...safeguard critical defense technologies. As incident commander when needed, you will drive... 
    Senior

    Slope

    Seattle, WA
    4 days ago
  • Axon in Seattle is seeking a Senior Security Operations Engineer II to join the security team responsible for detecting and responding to threats. The role emphasizes building and tuning tools to spot intrusions and lead incident response efforts. You're part of a high... 
    Senior
    Worldwide

    Security Services Worldwide

    Seattle, WA
    4 days ago
  • Sound Transit seeks a Senior Public Safety & Security Field Activity Specialist in Seattle, WA. The role includes leading shifts, coordinating training, and performing comprehensive...  ...system. You will conduct patrols, respond to incidents, and ensure safety through... 
    Senior
    Shift work

    ST Public Branding

    Seattle, WA
    3 days ago
  • $180k - $230k

     ...beneficial AI systems. About The Role We are seeking an Incident & Crisis Management Lead to join Anthropic's Global Safety, Intelligence, and Security...  ...program, equipping the company to prevent, prepare for, respond to, and recover from incidents and crises that could... 
    Flexible hours
    Night shift
    Afternoon shift

    Anthropic

    Seattle, WA
    2 days ago
  • Anduril Industries is seeking a Senior Security Operations Analyst for its Detection and Response team. You will monitor alerts across endpoints, cloud, and SaaS, respond to incidents, and act as an incident commander when needed. You will develop detection signatures,... 
    Senior

    Anduril Industries

    Seattle, WA
    5 days ago
  • Fluidstack seeks a senior incident commander to lead end-to-end security incidents in a 24/7 US region. You will own the on-call rotation, drive escalations...  ...remediation. You will build and mentor a team of senior responders, set high standards for incident handling, and ensure... 
    Senior

    Fluidstack

    Seattle, WA
    3 days ago
  • $330k - $380k

     ...history, and being responsible for the physical and logical security of that work makes everything else feel small. Role Scope Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication... 
    Permanent employment

    FluidStack

    Seattle, WA
    2 days ago
  •  ...mitigation and response planning, and expert program management across domestic emergency systems. The position involves training design, incident analysis, and 24/7 crisis monitoring support, with opportunities to contribute to After Action Reports and executive briefs across... 
    Senior
    Work at office

    Delaware Nation Industries

    Seattle, WA
    3 days ago
  •  ...This role manages access control, video management, visitor management, badging operations, and incident response, reporting to the Head of Physical Security. You will lead security programs, personnel, and crisis management while collaborating with Admin, Real Estate... 
    Senior
    Work at office

    TikTok USDS Joint Venture

    Seattle, WA
    1 day ago
  • $176k - $253k

     ...of how work gets done.We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated...  ...engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and... 
    Senior

    Snowflake

    Bellevue, WA
    3 days ago
  • $139.3k - $208k

    Prime Video is searching for a Senior Incident Manager. This senior-level incident management role is responsible for leading the incident response function for Prime Video's video...  ...globally distributed team is ready to respond 24x7. Actively mentor and develop the junior... 
    Senior
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  • Robinhood is seeking a Senior Software Engineer to join the Command Center in New York. You will lead reliability and observability initiatives across Robinhood’s infrastructure...  ...with multiple engineering teams to improve incident response and service quality. The role... 
    Senior

    Robinhood

    Bellevue, WA
    9 hours ago
  •  ...security professional in the United States (Washington) to perform access control, enforce policies, patrol premises, and report incidents per contract requirements. You will interact with clients, visitors and officials while maintaining safety standards and exceptional... 
    Senior
    Contract work

    Admiral Security Services

    Seattle, WA
    4 days ago
  •  ...Fluidstack in Seattle, WA is seeking a Senior Security Incident Response Lead to secure frontier compute infrastructure and drive end-to-end IR across corporate, cloud, and data center environments. You will build detection logic and response playbooks, run investigations... 
    Permanent employment

    FluidStack

    Seattle, WA
    1 day ago
  • $78k - $155k

     ...GENERAL PURPOSE: Under general direction, the Senior Contracts Specialist performs the full...  ...in area of assignment for the Agency; leads or assists Agency departments and project...  ...contracts; performs specification reviews; responds to questions and issues and provides... 
    Senior
    Full time
    Contract work
    Work at office
    Local area

    ST Public Branding

    Seattle, WA
    3 days ago
  •  ...their resources, and support them as they lead. Pivotal includes Pivotal Philanthropies,...  ...ROLE DESCRIPTION The Interim Senior Lead, Program Strategy, Planning & Management...  ...conducting research and analysis of data to respond to requests. Team Culture Serve as culture... 
    Senior
    Contract work
    Interim role
    Work at office
    Local area

    Pivotal

    Seattle, WA
    5 days ago
  • $210k - $256.67k

     ...breakthrough results.The RoleWe are looking for Program Director, to lead a large & complex multi pillar Oracle fusion cloud...  ...conferences, forums, thought leadership articles etc.Ability to work at a senior level within complex organisations, able to build empathy,... 
    Senior
    Full time
    Temporary work

    Infosys Technologies

    Seattle, WA
    1 day ago
  • Oracle’s Cloud Infrastructure division in Seattle seeks a Senior Principal Product Manager to own the vision, strategy, and execution for...  ...how customers leverage next-gen cloud services at scale. You’ll lead a cross-functional, data-driven effort to deliver mission-... 
    Senior

    Oracle

    Seattle, WA
    4 days ago
  • $158k - $217k

    Snowflake Partner Solution Lead - West RegionAs a Snowflake Partner Solution Lead, you will take the helm of one of Slalom’s most critical...  ...and 7-time Snowflake Partner of the Year, you will act as a senior technical and commercial authority at the intersection of... 
    Senior
    Temporary work
    Local area

    Slalom

    Seattle, WA
    1 day ago
  • Anthropic is seeking a Technical Program Manager to own and evolve incident management within the Detection & Response (D&R) team. You will drive the incident lifecycle from detection and triage through containment, remediation, and post-incident review, ensuring improvements... 
    Senior

    Anthropic

    Seattle, WA
    5 days ago
  • JPMorganChase is looking for a Technology Support Lead to join the Cybersecurity & Technology Controls team in Seattle, WA. You will play a crucial role in managing cybersecurity incidents and support operations 24/7. Ideal candidates will bring at least five years of... 

    JPMorganChase

    Seattle, WA
    2 days ago
  •  ...Mandiant unit seeks a Security Consultant with strong leadership in incident response and remediation. You'll guide clients through complex...  ...while coordinating with cross-functional teams. You will lead engagements, communicate effectively with stakeholders at all levels... 
    Remote job

    Google

    Seattle, WA
    4 days ago
  • Anthropic is seeking an Incident & Crisis Management Lead to join the GSIS team to operationalize the crisis management program across physical, supply chain, operational, and reputational threats. You will ensure the right stakeholders are engaged during incidents that... 

    Anthropic

    Seattle, WA
    2 days ago
  •  ...drive reliability across Azure-based microservices. You will establish SLOs/SLIs, observability standards, and governance, and lead major incidents and postmortems to push for systemic improvements. You will also guide capacity planning, resiliency design, automation, and... 

    Tata Consultancy Services

    Bellevue, WA
    2 days ago
  • Principal or Senior Principal, Anthropic AI SolutionsAI Systems & Platforms | Anthropic Business Unit****Please note: This role is not...  ...to solve meaningful problems. As the Anthropic Partner Solution Lead, you’ll partner with cross-functional teams, including industry... 
    Senior
    Temporary work
    Work at office
    Local area

    Slalom

    Seattle, WA
    4 days ago
  • $142.5k - $190k

    JPMorgan Chase in Seattle is seeking a Technology Support Lead to provide critical support within the Cybersecurity Incident Management team. This role involves managing cybersecurity incidents, executing firm-wide strategies, and enhancing technological resilience. Ideal... 
    Senior

    JPMorgan Chase

    Seattle, WA
    5 days ago
  • Robinhood is seeking a Senior Software Engineer for the Robinhood Command Center to lead reliability and observability across its infrastructure. You will collaborate with multiple engineering teams, drive incident response improvements, and own tooling and governance for... 
    Senior

    Robinhood

    Bellevue, WA
    9 hours ago
  •  ...seeking an experienced CSIRT Investigator to join its security team in the United States. You will identify and investigate security incidents, contribute to improving incident response, and participate in on‑call rotations as part of a large enterprise environment. The... 
    Senior
    Work at office
    Remote work

    DocuSign

    Seattle, WA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Lead Incident Responder. Be the first to apply!