Salesforce logo
SalesforcePosted 1 week ago

Senior Lead Incident Responder

$172,500–$260,100 year

On-siteSeattle, Washington, United States

Full TimeSenior LevelEnterprise

Job Summary

Own the analytical core of major incident investigations by reconstructing threat actor actions from large, messy multi-source datasets using Splunk, SQL, and custom correlation. Serve as the team's primary analyst for complex cases involving credential compromise, data exfiltration, and API abuse, building defensible timelines and CAN reports that withstand legal scrutiny. Lead containment actions and hostile customer communications while engineering new detections for identified TTPs. Review Grade 6/7 case work to mentor junior responders and support CREST's AI-first initiatives. Requires 8+ years in hands-on incident response with deep expertise in forensic techniques and Salesforce ecosystems. Base salary $172,500 - $260,100 annually.

Required Qualifications

  • 8+ years in security incident response with consistent hands-on technical case work
  • currently performing investigations, not purely managing or coordinating
  • Demonstrated ability to take large, messy, multi-source data and independently produce a correct, defensible account of what happened
  • Expert log analysis — Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation
  • Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents
  • Deep technical knowledge in systems, networks, cloud security, and forensic techniques
  • Demonstrated composure and judgment across multiple concurrent high-pressure investigations
  • Strong familiarity with Salesforce products/ecosystems, or comparable multi-tenant SaaS platforms
  • Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently
  • Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA)
  • Proven ability to lead cross-functional investigations and deliver clear, defensible outcomes

Desired Qualifications

  • Salesforce Admin certified
  • 3–5 years in a lead or senior IR role within a large, global organization
  • Experience with complex forensic cases involving large datasets or unusual/novel data sources
  • Hands-on experience with AI/automation tooling in security operations (automated triage, detection tuning, agentic workflows)
  • Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent)
  • Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure)
  • Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce