Senior Lead Incident Responder
$172.5k - $260.1kSalesforce
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Job Category
Enterprise Technology & InfrastructureJob Details
About Salesforce
Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.
Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.
The Experience:
This is CREST's analysis anchor. The primary job is investigation — but specifically the hard analytical core of it: taking a messy, high-volume, multi-source pile of log data and figuring out what actually happened, what the threat actor touched, and what was truly at risk. We're hiring for analytical horsepower first. The right person is someone who is genuinely a killer in analysis — they see the pattern in the noise faster than anyone in the room, build a defensible timeline from incomplete evidence, and can prove what happened rather than guess at it. Operational coordination and customer work are part of the role, but they sit on top of a foundation of elite investigative analysis. If you're an investigator who runs to the data, this role is built for you.
What You'll Actually Be Doing:
- Own the analytical hardest-part of major investigations — take large, messy, multi-source datasets (Splunk, SQL, UIP/MonC, API/login/export logs) and reconstruct exactly what the threat actor did, what they accessed, and what was at risk.
- Serve as the team's go-to analyst on complex or ambiguous cases — the person others bring a stalled investigation to when the data isn't giving up its answer easily.
- Perform expert log analysis independently: complex multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivoting across data sources under time pressure.
- Build accurate, complete, and defensible investigation timelines and CAN reports — analysis that holds up to legal and regulatory scrutiny.
- Lead investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud — ATO, credential compromise, data exfiltration, API abuse, connected app exploitation.
- Approve and execute strategic containment actions (credential rotation, IP blocks, OAuth revocation, escalated platform actions) with appropriate stakeholder coordination.
- Lead hostile and contentious customer calls, including those with legal counsel or regulatory pressure, and communicate complex technical findings clearly.
- Engineer net-new detections for newly identified TTPs; turn what you find in analysis into durable detection coverage with Detection Engineering.
- Raise the analytical bar on the team — review Grade 6/7 case work, give structured written feedback on investigative rigor, and mentor junior responders on advanced analysis technique.
- Support CREST's AI-first initiatives — use and help improve automated agents for triage, documentation, and investigation workflows.
- Collaborate with Threat Intelligence, Detection Engineering, and Legal on incident handling and cross-functional initiatives.
You're Our Person If You Have:
- 8+ years in security incident response with consistent hands-on technical case work; currently performing investigations, not purely managing or coordinating.
- Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened. We will weight this above every other qualification.
- Expert log analysis — Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation — performed independently, fast, without assistance.
- Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.
- Deep technical knowledge in systems, networks, cloud security, and forensic techniques.
- Demonstrated composure and judgment across multiple concurrent high-pressure investigations.
- Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms.
- Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.
- Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).
- Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes.
Even Better If You Have:
- Salesforce Admin certified.
- 3–5 years in a lead or senior IR role within a large, global organization.
- Experience with complex forensic cases involving large datasets or unusual/novel data sources — the harder the data, the better.
- Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows).
- Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent).
- Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure).
- Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns.
Unleash Your Potential
When you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and resources support you to find balance and be your best , and our AI agents accelerate your impact so you can do your best . Together, we’ll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future — but to redefine what’s possible — for yourself, for AI, and the world.
Accommodations
If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this Accommodations Request Form .
Please note that Salesforce uses artificial intelligence (AI) tools to help our recruiters assess and evaluate candidates’ resumes and qualifications throughout the recruiting process. Humans will always make any candidate selection and hiring decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including with regard to use of AI tools and opt out options.
Posting Statement
Salesforce is an equal opportunity employer and maintains a policy of non-discrimination with all employees and applicants for employment. What does that mean exactly? It means that at Salesforce, we believe in equality for all. And we believe we can lead the path to equality in part by creating a workplace that’s inclusive, and free from discrimination. Know your rights: workplace discrimination is illegal. Any employee or potential employee will be assessed on the basis of merit, competence and qualifications – without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.
In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: Salesforce, we believe in equitable compensation practices that reflect the dynamic nature of labor markets across various regions. The typical base salary range for this position is $172,500 - $260,100 annually. The range represents base salary only, and does not include company bonus, incentive for sales roles, equity or benefits, as applicable.- Providence Health & Services in Renton, WA seeks a senior information security leader to guide enterprise security programs, risk management... ...budget. The role emphasizes hands-on security risk management, incident response readiness, and ongoing metrics reporting to senior...Senior
- Salesforce is seeking a Senior Analyst for the Critical Customer Response (CCR) team in Bellevue, WA. The role focuses on translating complex technical incidents into clear business updates for customers, executives, and internal teams, ensuring information is timely, accurate...Senior
- ...operational environment, strong analytical capabilities, and effective communication skills. You will be responsible for analyzing security incidents, creating automations for security operations tools, and ensuring compliance with industry standards. If you're passionate about...Senior
- ...la résolution des pannes Avaya et MS Teams, avec escalade coordonnée et communication fluide entre les groupes. Vous gérerez les incidents, documenterez les procédures et contribuerez à l’amélioration continue des systèmes de communication d’entreprise, tout en respectant...Senior
$180k - $230k
...beneficial AI systems. About The Role We are seeking an Incident & Crisis Management Lead to join Anthropic's Global Safety, Intelligence, and Security... ...program, equipping the company to prevent, prepare for, respond to, and recover from incidents and crises that could...SuggestedFlexible hoursNight shiftAfternoon shift- Fluidstack seeks a senior incident commander to lead end-to-end security incidents in a 24/7 US region. You will own the on-call rotation, drive escalations... ...remediation. You will build and mentor a team of senior responders, set high standards for incident handling, and ensure...Senior
$330k - $380k
...history, and being responsible for the physical and logical security of that work makes everything else feel small. Role Scope Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication...Permanent employment$176k - $253k
...of how work gets done.We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated... ...engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and...Senior- ...mitigation and response planning, and expert program management across domestic emergency systems. The position involves training design, incident analysis, and 24/7 crisis monitoring support, with opportunities to contribute to After Action Reports and executive briefs across...SeniorWork at office
$139.3k - $208k
Prime Video is searching for a Senior Incident Manager. This senior-level incident management role is responsible for leading the incident response function for Prime Video's video... ...globally distributed team is ready to respond 24x7. Actively mentor and develop the junior...SeniorFlexible hours- Robinhood is seeking a Senior Software Engineer to join the Command Center in New York. You will lead reliability and observability initiatives across Robinhood’s infrastructure... ...with multiple engineering teams to improve incident response and service quality. The role...Senior
- ...Okta is seeking an experienced Auth0 Trust Incident Manager to join their Bellevue team. This role focuses on managing incidents, improving customer experience, and collaborating with various teams to resolve issues effectively. Candidates should have a background in...SeniorWork at office
- Principal or Senior Principal, Anthropic AI SolutionsAI Systems & Platforms | Anthropic Business Unit****Please note: This role is not... ...to solve meaningful problems. As the Anthropic Partner Solution Lead, you’ll partner with cross-functional teams, including industry...SeniorTemporary workWork at officeLocal area
- Oracle’s Cloud Infrastructure division in Seattle seeks a Senior Principal Product Manager to own the vision, strategy, and execution for... ...how customers leverage next-gen cloud services at scale. You’ll lead a cross-functional, data-driven effort to deliver mission-...Senior
- Anthropic is seeking an Incident & Crisis Management Lead to join the GSIS team to operationalize the crisis management program across physical, supply chain, operational, and reputational threats. You will ensure the right stakeholders are engaged during incidents that...
- Fluidstack in Seattle, WA is seeking a Senior Security Incident Response Lead to secure frontier compute infrastructure and drive end-to-end IR across corporate, cloud, and data center environments. You will build detection logic and response playbooks, run investigations...Permanent employment
- ...drive reliability across Azure-based microservices. You will establish SLOs/SLIs, observability standards, and governance, and lead major incidents and postmortems to push for systemic improvements. You will also guide capacity planning, resiliency design, automation, and...
- ...Mandiant unit seeks a Security Consultant with strong leadership in incident response and remediation. You'll guide clients through complex... ...while coordinating with cross-functional teams. You will lead engagements, communicate effectively with stakeholders at all levels...Remote job
- JPMorganChase is looking for a Technology Support Lead to join the Cybersecurity & Technology Controls team in Seattle, WA. You will play a crucial role in managing cybersecurity incidents and support operations 24/7. Ideal candidates will bring at least five years of...
- JPMorgan Chase & Co. is seeking a Technology Support Lead within the Cybersecurity & Technology Controls team in Seattle. In this role, you will provide crucial support for incident management, ensuring robust cybersecurity strategies are in place. You will work closely...
$142.5k - $190k
JPMorgan Chase in Seattle is seeking a Technology Support Lead to provide critical support within the Cybersecurity Incident Management team. This role involves managing cybersecurity incidents, executing firm-wide strategies, and enhancing technological resilience. Ideal...Senior$153.6k - $192k
...seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that... ...and upskill IT and its partners by producing documentation and leading training sessionsEvangelize best practices both internally and...SeniorWork at officeImmediate startRemote workWork from home- ...service while ensuring safety standards are met. The role involves performing the duties of a Security Officer, including initial incident response, investigations, and interviews, with emphasis on collaboration across teams to support the #J-18808-Ljbffr Providence Swedish
- Robinhood is seeking a Senior Software Engineer for the Robinhood Command Center to lead reliability and observability across its infrastructure. You will collaborate with multiple engineering teams, drive incident response improvements, and own tooling and governance for...Senior
- ...oversee the Security Department's workflow, ensuring quality service and a safe environment at Swedish Ballard in Seattle. You will lead incident responses, conduct interviews and investigations while guiding a team to uphold strict standards in alignment with our mission...Full timeDay shift
- ...global professional services and solutions company that helps leading organizations reinvent with digital, cloud, data, and AI capabilities... ...business outcomes at speed and scale.You Are:We are seeking a Senior Ontologist and Knowledge Architecture Leadto own the design,...SeniorFull timeLive inWork at officeLocal area
$148.7k - $201.2k
Amazon Web Services (AWS) is seeking a talented, strategically-minded, and self-motivated Senior Manufacturing Environmental Program Integration Lead to support AWS Manufacturing, Test, and Operations (MOTO) facilities. The successful candidate will join the AWS Environmental...SeniorFlexible hoursDay shift- Senior Business Analyst Team Lead (POD Lead) Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the... ...3rd Party vendor applications. The right candidate: Can respond to a rapidly changing business environment and can take...SeniorRemote work
- Jobtailor is seeking a seasoned professional to manage incident communications, translating complex technical details into business-facing updates. You will coordinate across engineering, support, and executives to ensure timely, accurate information during incidents....Senior
- Salesforce is seeking a Senior Analyst for the Critical Customer Response (CCR) team to communicate with customers and executives during high-impact incidents. You will translate complex technical issues into clear updates, consolidate cross-functional information, and...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Lead Incident Responder. Be the first to apply!
- senior lead project manager Seattle, WA
- senior robotics software engineer Seattle, WA
- senior devops engineer remote Seattle, WA
- senior sas administrator Seattle, WA
- senior IT manager Seattle, WA
- senior director of client services Seattle, WA
- senior contracts analyst Seattle, WA
- senior implementation consultant Seattle, WA
- sr project manager Seattle, WA
- senior windows systems engineer Seattle, WA

