Director, Customer Security Response

Salesforce Salesforce · Enterprise · Bellevue, WA +1

This role leads customer security investigations and incident response for Salesforce customers in the APAC and US West regions. It involves hands-on technical analysis, leading complex incidents end-to-end, managing a team, and driving cross-functional engagement. The role also focuses on transitioning from manual investigations to AI-driven automated triage and scoping, and potentially managing AI and automation programs within security operations.

What you'd actually do

  1. Personally lead the most complex customer security investigations across APAC and US West, including multi-cloud data exfiltration scoping, novel attacker tactics, techniques, and procedures (TTPs), and advanced API abuse — using tools like Splunk and SQL to determine scope, timeline, and exfiltration vectors.
  2. Serve as the final technical authority on containment decisions for the region, including credential rotation, OAuth revocation, IP blocks, and deployment moratoriums, and lead high-stakes customer calls — including those involving legal counsel or regulatory pressure — without requiring senior escalation.
  3. Own regional operations including staffing, capacity planning, on-call scheduling, and case assignment, while setting quality standards for investigation documentation and customer-facing notifications across APAC and US West.
  4. Drive cross-functional engagement with Detection Engineering, Threat Intelligence, Product Security, and Legal to close detection gaps, and lead the team's transition from manual investigation to AI-driven automated triage and scoping.

Skills

Required

  • 10+ years in information security
  • 5+ years leading hands-on incident response
  • currently performing technical investigations
  • independently scope data exfiltration across APIs, bulk exports, and connected apps in multi-tenant SaaS environments
  • write complex multi-source Splunk and SQL queries, including regex-based correlation
  • demonstrated track record of leading complex, high-severity incidents end-to-end
  • built and managed high-performing, globally distributed security teams
  • influence cross-functionally across Engineering, Legal, Product, and customer-facing organizations

Nice to have

  • managing AI and automation programs within security operations
  • agentic workflows
  • detection automation
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Offensive Security Certified Professional (OSCP)
  • Certified Information Systems Security Professional (CISSP)
  • deep familiarity with the Salesforce platform ecosystem
  • advanced threat hunting
  • behavioral modeling
  • detection engineering programs

What the JD emphasized

  • regulatory notification
  • Global Data Protection Regulation (GDPR)
  • Digital Operational Resilience Act (DORA)
  • state breach notification laws