Senior Lead Incident Responder

Salesforce
Seattle
Full timeUSD 172,500 - 260,100 annuallyFunction: Administration & Executive AssistanceExperience: 8+ yearsSkills: ["Composed under pressure","Analytical rigor","Cross-functional communication","Customer communication","Judgment"]

Investigate complex, high-volume, multi-source security incidents by reconstructing exactly what happened, what was accessed, and what was at risk. Lead deep log analysis using Splunk, SQL, and APIs to produce defensible timelines and CAN reports for legal/regulatory scrutiny. Handle advanced incidents (ATO, credential compromise, data exfiltration, API abuse), drive containment actions, approve detections for new TTPs, and mentor junior responders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Salesforce
Salesforce
1 day ago

Senior Lead Incident Responder

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Investigate complex, high-volume, multi-source security incidents by reconstructing exactly what happened, what was accessed, and what was at risk. Lead deep log analysis using Splunk, SQL, and APIs to produce defensible timelines and CAN reports for legal/regulatory scrutiny. Handle advanced incidents (ATO, credential compromise, data exfiltration, API abuse), drive containment actions, approve detections for new TTPs, and mentor junior responders.
Location: Seattle
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Own the analytical hardest-part of major investigations using large, messy, multi-source datasets to reconstruct threat actor actions and impact.
  • •Serve as the go-to analyst on complex or ambiguous cases when investigations stall.
  • •Perform independent expert log analysis including multi-source joins, regex parsing, custom correlation, and hypothesis-driven pivots under time pressure.
  • •Build accurate, complete, defensible investigation timelines and CAN reports suitable for legal and regulatory scrutiny.
  • •Lead investigations into high-impact incidents (ATO, credential compromise, data exfiltration, API abuse, connected app exploitation) and approve containment actions with stakeholder coordination.

Pay and Benefits

Salary: USD 172,500 - 260,100 annually
Perks:MedicalDentalVisionHealth InsurancePaid ParentalLife InsuranceDisability Insurance401kEquity

Key Requirements

  • •8+ years in security incident response with consistent hands-on technical case work focused on investigations, not purely coordination.
  • •Expert log analysis using Splunk/SQL, including complex multi-source joins, regex parsing, and custom correlation.
  • •Experience handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.
  • •Deep technical knowledge of systems, networks, cloud security, and forensic techniques.
  • •Strong familiarity with compliance standards including GDPR, PCI-DSS, and DORA.
Experience:8+ yearsSecurity incident responseForensicsCloud securitySaaSThreat intelligence
Skills:Composed under pressureAnalytical rigorCross-functional communicationCustomer communicationJudgment
Certifications:Salesforce AdminSANS GCFASANS GNFASANS GCIHOSCP
Tech Stack:SplunkSQLAPIOAuthRegex parsingMulti-source correlationDetection EngineeringSalesforceGDPRPCI-DSSDORA

Company Brief

Salesforce
Provides a leading cloud-based customer relationship management (CRM) platform with sales, service, marketing, analytics, and integration tools that empower businesses to manage customer relationships and digital transformation at scale.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1999
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor