Information Security | Lead Incident Responder
Salesforce - India - Hyderabad
Posted Jun 12, 2026
Benefits
- Parental leave
- 26 weeks From the posting source checked Jun 20, 2026
- Non-birth-parent leave
- 12 weeks From the posting source checked Jun 20, 2026
- Family-building benefits
-
- Fertility benefits: Not verified
- Adoption assistance: Not verified
- Surrogacy assistance: Not verified
- Mental health support
- Not verified
- Relocation assistance
- Not verified
- Childcare support
- Not verified
- Learning budget
- Not verified
- Verification
- Source-linked checked May 7, 2026
- Salary
- Not verified
- 401(k) match
- Reported from DOL Form 5500 industry filing (not employer-specific)
Was this benefit information wrong? Tell us.
Market context
- U.S. role benchmark (BLS OEWS)
- $116,543 U.S. median for this role
- Projected growth (BLS Employment Projections)
- +9.8% - Much faster than average
Matched to SOC 15-1252 - Software Engineering aggregate by role bucket.
Source: U.S. Bureau of Labor Statistics, OEWS, May 2024 and Employment Projections, 2024-2034.
Role
Schedule
- Shift type
- Not verified
- Weekend work
- Not verified
Company
Application
- Cover letter
- Not verified
- Assessment
- Not verified
- Deadline
- Not stated
Where they hire
State eligibility is not yet verified.
About this role
Information Security | Lead Incident Responder India - Hyderabad Role Summary The Lead Incident Responder is the senior technical IC on CREST's EMEA/India region. The primary job is investigating customer security incidents - performing log analysis, scoping data exfiltration, leading containment, and running customer calls on complex or hostile cases. This is not a people management role. Regional coordination responsibilities (on-call scheduling, case assignment, shift handoff quality) are part of the job, but the expectation is that this person is in the queue working cases daily. Technical depth and speed under pressure matter more than management experience. The right candidate is an investigator who can also run ops. Responsibilities Lead investigations into advanced or high-impact security incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud. Personally carry a caseload daily - perform log analysis, scope exfiltration, build investigation timelines, and drive containment on active incidents. Serve as primary technical authority on complex investigations in EMEA/India, coordinating response across internal stakeholders and technical SMEs. Analyze large and complex datasets (Splunk, SQL, UIP/MonC) to identify indicators of compromise, exfiltration patterns, and attacker TTPs. Approve and execute strategic containment actions - credential rotation, IP blocks, OAuth revocation, and escalated platform actions - with appropriate stakeholder coordination. Lead hostile and contentious customer calls, including those involving legal representation or regulatory pressure, and de-escalate independently. Coordinate EMEA/India regional operations: on-call scheduling, case assignment, and shift handoff quality. Drive the growing ATO caseload, including proactive notification workflows and containment actions. Engineer net-new DSEC/Asgard detections for newly
Read the full description at careers.salesforce.com. FewerJobs shows a preview and links to the original posting.
Apply link not verified; last-live date unavailable.
What verified means
Verified means a displayed claim has field-level provenance to a source FewerJobs pulled: a government or employer source, or the original job posting. Posting-sourced facts are employer-stated and are labeled separately from government records.
Related jobs
-
Detection and Response Engineer
Unisys CORP - Home Based India
-
Detection and Response Engineer
Navan INC - Gurugram, IN
-
Senior Citrix Engineer - Lead
Accendra Health INC - 3610 Accendra India
-
Lead IT Architect
Honeywell - Hyderabad, Telangana, India