Information Security | Lead Incident Responder

Salesforce Salesforce · Enterprise · Hyderabad, India

Salesforce is seeking a Lead Incident Responder to investigate customer security incidents, perform log analysis, scope data exfiltration, lead containment, and manage customer calls. This role involves regional coordination, but the primary focus is on hands-on technical case work. The candidate will analyze complex datasets, approve strategic containment actions, lead customer calls, and assist with regulatory notifications. The role also involves developing new detections and mentoring junior analysts, with a focus on leveraging AI agents for security operations.

What you'd actually do

  1. Lead investigations into advanced or high-impact security incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud.
  2. Personally carry a caseload daily — perform log analysis, scope exfiltration, build investigation timelines, and drive containment on active incidents.
  3. Serve as primary technical authority on complex investigations in EMEA/India, coordinating response across internal stakeholders and technical SMEs.
  4. Analyze large and complex datasets (Splunk, SQL, UIP/MonC) to identify indicators of compromise, exfiltration patterns, and attacker TTPs.
  5. Approve and execute strategic containment actions — credential rotation, IP blocks, OAuth revocation, and escalated platform actions — with appropriate stakeholder coordination.

Skills

Required

  • 8+ years of experience in security incident response, with consistent hands-on technical case work throughout career progression.
  • Expertise handling Account Takeover, credential compromise, data exfiltration, API abuse, and connected app exploitation incidents.
  • Deep technical knowledge in systems, networks, cloud security, and forensic techniques.
  • Ability to lead customer calls and communicate complex technical findings to non-technical audiences clearly and confidently.
  • Proven ability to lead cross-functional investigations and deliver clear outcomes.

Nice to have

  • Salesforce Admin certified.
  • 3–5 years of experience in a lead or senior incident response role within a large, global organization.
  • Experience with e-commerce security or cloud-native environments (AWS, GCP, Azure).
  • Experience with complex forensic cases involving large datasets or unusual data sources.
  • Hands-on experience with AI/automation tooling in security operations — automated triage, detection tuning, or agentic workflows.
  • Advanced certifications (SANS GCFA, GNFA, GCIH, OSCP, or equivalent).
  • Familiarity with Marketing Cloud and Commerce Cloud log analysis and incident patterns.
  • Prior experience coordinating regional on-call rotations and shift handoff processes.

What the JD emphasized

  • Currently performing investigations — not purely managing or coordinating. Must demonstrate recent, direct case work and log analysis.
  • Expert log analysis skills — Splunk/SQL including complex multi-source joins, regex parsing, and custom correlation — performed independently without assistance.
  • Strong understanding of regional and global compliance standards (GDPR, PCI-DSS, DORA).