FewerJobs.
All jobs

Information Security | Lead Incident Responder

Salesforce - India - Hyderabad

Posted Jun 12, 2026

Benefits

Parental leave
26 weeks From the posting source checked Jun 20, 2026
Non-birth-parent leave
12 weeks From the posting source checked Jun 20, 2026
Family-building benefits
  • Fertility benefits: Not verified
  • Adoption assistance: Not verified
  • Surrogacy assistance: Not verified
Mental health support
Not verified
Relocation assistance
Not verified
Childcare support
Not verified
Learning budget
Not verified
Verification
Source-linked checked May 7, 2026
Salary
Not verified
401(k) match
Reported from DOL Form 5500 industry filing (not employer-specific)

Was this benefit information wrong? Tell us.

Market context

U.S. role benchmark (BLS OEWS)
$116,543 U.S. median for this role
Projected growth (BLS Employment Projections)
+9.8% - Much faster than average

Matched to SOC 15-1252 - Software Engineering aggregate by role bucket.

Source: U.S. Bureau of Labor Statistics, OEWS, May 2024 and Employment Projections, 2024-2034.

Role

Role function
Engineering From the posting source checked Jun 20, 2026
Seniority
Senior From the posting source checked Jun 20, 2026

Schedule

Shift type
Not verified
Weekend work
Not verified

Company

Company stage
Public-company From the posting source checked Jun 20, 2026
Equity
Offered Verified - SEC 10-K source checked Jun 20, 2026

Application

Cover letter
Not verified
Assessment
Not verified
Deadline
Not stated

Where they hire

State eligibility is not yet verified.

About this role

Information Security | Lead Incident Responder India - Hyderabad Role Summary The Lead Incident Responder is the senior technical IC on CREST's EMEA/India region. The primary job is investigating customer security incidents - performing log analysis, scoping data exfiltration, leading containment, and running customer calls on complex or hostile cases. This is not a people management role. Regional coordination responsibilities (on-call scheduling, case assignment, shift handoff quality) are part of the job, but the expectation is that this person is in the queue working cases daily. Technical depth and speed under pressure matter more than management experience. The right candidate is an investigator who can also run ops. Responsibilities Lead investigations into advanced or high-impact security incidents across Salesforce Core, Marketing Cloud, and Commerce Cloud. Personally carry a caseload daily - perform log analysis, scope exfiltration, build investigation timelines, and drive containment on active incidents. Serve as primary technical authority on complex investigations in EMEA/India, coordinating response across internal stakeholders and technical SMEs. Analyze large and complex datasets (Splunk, SQL, UIP/MonC) to identify indicators of compromise, exfiltration patterns, and attacker TTPs. Approve and execute strategic containment actions - credential rotation, IP blocks, OAuth revocation, and escalated platform actions - with appropriate stakeholder coordination. Lead hostile and contentious customer calls, including those involving legal representation or regulatory pressure, and de-escalate independently. Coordinate EMEA/India regional operations: on-call scheduling, case assignment, and shift handoff quality. Drive the growing ATO caseload, including proactive notification workflows and containment actions. Engineer net-new DSEC/Asgard detections for newly

Read the full description at careers.salesforce.com. FewerJobs shows a preview and links to the original posting.

Apply at careers.salesforce.com

Apply link not verified; last-live date unavailable.

What verified means

Verified means a displayed claim has field-level provenance to a source FewerJobs pulled: a government or employer source, or the original job posting. Posting-sourced facts are employer-stated and are labeled separately from government records.

Related jobs