908,794open jobs
55,875companies
151,787added this week
Browse all
Salary
≈ $56k – $139k per year (Estimated)
Location
Remote (United Kingdom)
Seniority
Middle · 2+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Sep 25, 2026. Sophos scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

Sophos is seeking an intermediate-level Incident Response Analyst to support its Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT).

As an Incident Response Analyst 2, you will perform advanced investigative, forensic, and containment activities during active cyber incidents. You will operate with moderate autonomy, serve primarily in an Incident Responder role, and begin supporting Incident Advisors with validated technical findings and customer-facing context. This role serves as the technical backbone of most engagements and includes mentoring junior analysts to ensure consistent execution and documentation quality.

What You Will Do

  • Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry
  • Execute containment and response actions to neutralize active threats as directed by Incident Advisors or Senior Analysts
  • Validate indicators of compromise (IOCs) and correlate alerts, artifacts, and telemetry to determine scope and root cause
  • Maintain clear and accurate engagement documentation, including trailheads, timelines, and playbooks
  • Provide guidance and mentorship to junior IR and SOC analysts to ensure adherence to CIRT investigative and documentation standards
  • Prepare technical findings and summaries for inclusion in customer updates and post-incident reports
  • Identify and communicate detection or response gaps observed during investigations
  • Participate in shift handovers, debriefs, and post-incident reviews to ensure engagement continuity
  • Maintain accurate time and activity tracking to support operational visibility and service improvement

What You Will Bring

    Essential:

  • 2+ years of experience in incident response, MDR, SOC, or security operations roles
  • Solid technical understanding of endpoint forensics, log analysis, and common attack techniques
  • Experience investigating malware, credential theft, ransomware, or similar threats
  • Ability to correlate alerts and telemetry to determine incident scope and root cause
  • Strong written and verbal communication skills for documenting findings and contributing to customer updates
  • Experience mentoring or guiding junior analysts
  • Ability to work effectively in high-pressure, time-sensitive incident environments
  • Willingness to work some weekends and holidays as part of a rotation
  • Desired:

  • Hands-on experience with EDR, SIEM, and forensic collection tools
  • Familiarity with OSQuery, SQL, or KQL
  • Knowledge of MITRE ATT&CK and incident response frameworks
  • Industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent
  • Experience contributing to playbooks, detection tuning, or service improvement initiatives
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
908,794 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $104k – $210k per year (Estimated) • Remote (United States) • 5+ years exp • Bachelor's Degree
DevOps
Azure
DNS
Cybersecurity
FortiGate
SentinelOne
Apply
GRC Security Analyst 8 hours ago
$114k – $139k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree
AI/ML
Galileo
ISO 42001
Cybersecurity
ISO 27001
NIST CSF
SOC 2
GDPR
Apply
≈ $19k – $41k per year (Estimated) • Remote (India) • Full-Time • Bengaluru
AI/ML
LLM
Red Teaming
Edge AI
Machine Learning
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
MITRE ATT&CK
SOC 2
Cyber Kill Chain
SIEM
Apply
≈ $59k – $111k per year (Estimated) • Remote (United States) • Confidential • Full-Time • 3+ years exp • Bachelor's Degree • Little Rock
Analytics
Microsoft Excel
Apply
≈ $70k – $139k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Belfast
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
Crowdstrike
Microsoft Sentinel
ISO 27001
Microsoft Defender
MITRE ATT&CK
NIST CSF
SIEM
Management
Microsoft Teams
Apply
≈ $121k – $209k per year (Estimated) • Remote (United States)
Python
SQL
Databases
Snowflake
Databricks
DevOps
Terraform
GCP
Azure
AWS
Grafana
Cybersecurity
SIEM
QA
Sentry
Apply
$99k – $142k per year • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Boston
SQL
Databases
Snowflake
AI/ML
dbt
DevOps
GCP
Azure
CI/CD
AWS
Analytics
ETL/ELT
Management
Agile
Apply
SAP Training - Paid 3 hours ago
≈ $56k – $157k per year (Estimated) • Remote (United States, India, Canada)
SQL
ABAP
ABAP
SAP BTP
Databases
SAP BW
Apply
$103k – $128k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Boulder
SQL
AI/ML
Supervision
Analytics
SAP BusinessObjects
Management
Agile
Scrum
Waterfall
Service Desk
Microsoft Office
Apply
≈ $135k – $226k per year (Estimated) • Remote (United States) • Full-Time
Python
Java
Scala
Databases
MySQL
PostgreSQL
Snowflake
AI/ML
RAG
DevOps
Terraform
CloudFormation
AWS
Grafana
Amazon Kinesis
Cybersecurity
SIEM
Apply
Threat Analyst 2 4 days ago
≈ $54k – $135k per year (Estimated) • Remote (United Kingdom) • Full-Time • 2+ years exp • Bachelor's Degree
SQL
PowerShell
DevOps
Red Hat
Debian
Ubuntu
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Threat Analyst 1 6 days ago
≈ $60k – $131k per year (Estimated) • Remote (Canada) • Full-Time • 2+ years exp
SQL
PowerShell
DevOps
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Threat Analyst 2 7 days ago
≈ $15k – $36k per year (Estimated) • Remote (India) • Full-Time • 3+ years exp • Bachelor's Degree
Python
PowerShell
DevOps
Linux
Windows
TCP/IP
DNS
Cybersecurity
MITRE ATT&CK
Active Directory
SIEM
Apply
≈ $102k – $208k per year (Estimated) • Remote (Canada) • Full-Time • 10+ years exp
Python
SQL
PowerShell
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
≈ $19k – $41k per year (Estimated) • Remote (India) • Full-Time • 7+ years exp
JavaScript
SQL
PowerShell
Node JS
Node JS
Commander.js
Cybersecurity
Velociraptor
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
See all jobs
This is one of many
908,794 more open roles from verified company boards, updated every day.