368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$26k – $60k per year (Estimated)
Location
Remote (India)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

Sophos is seeking an experienced and motivated Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.

As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team.

In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.

At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.

The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.

What you will do

    • Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
    • Provide guidance to customers on best practices following an incident
    • Lead daily update calls for customers to deliver forensic findings
    • Deliver concise email updates to customers between update calls
    • Direct the forensic investigations, identify priorities, and delegate tasks to analysts
    • Conduct multiple Rapid Response incidents concurrently
    • Determine TTPs identified by analysts and add them to the threat intel platform
    • Write clear and concise Executive Summary style reports in a timely manner
    • Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
    • Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
    • This role will involve working from Friday to Tuesday (Wednesday & Thursday would be off).
    • It will involve working in fixed Morning Shift (6am to 3pm IST).

What you will bring

    • 5+ years of experience leading incident response investigations involving ransomware
    • Experience leading BEC investigations
    • Continuously learning and staying informed of the changing threat landscape
    • Proven track record of successful neutralization and remediation of ransomware threats
    • Excellent understanding of the Incident Response process
    • Excellent understanding of cyber risks and able to qualify them to customers
    • Excellent oral communication skills
    • Strong written communication skills
    • Ability to manage time effectively
    • Able to delegate and prioritize tasks across multiple incidents
    • Able to excel under stressful circumstances
    • Occasionally willing to begin work early and/or stay late when warranted for customer engagements
    • Strong grasp of the MITRE ATT&CK framework
    • Enjoy mentoring and assisting in the development of junior analysts
    • A team-player attitude with a willingness to share knowledge
    • Ability to work on weekends and holidays
    • Post-secondary education in Cybersecurity, comparable
    • Desirable:

    • Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
    • Experience with SIEM technology (e.g. Splunk, ELK, etc.)
    • Willingness to work occasional overtime during peak times or holidays
    • Experience writing SQL queries
    • Experience writing PowerShell, Python, or Bash scripts
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Cybersecurity Manager 3 hours ago
$113k – $227k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Lake Forest • Saint Paul • Chicago
Cybersecurity
CVSS
FedRAMP
GDPR
ISO 27001
MITRE ATT&CK
SOC 2
Apply
$60k – $149k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Ottobrunn • Ulm
Python
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
Инженер SIEM 6 hours ago
$22k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • Moscow
Bash
Python
Cybersecurity
MITRE ATT&CK
Apply
$17k – $21k per year (Estimated) • Remote/Hybrid • Full-Time • Bucharest
DevOps
Azure
GCP
Incident Management
Splunk
Cybersecurity
Google SecOps
MITRE ATT&CK
Apply
$20k – $44k per year (Estimated) • Remote • Full-Time • 5+ years exp • Minsk
Bash
PowerShell
Python
DevOps
AWS
Azure
Azure DevOps
Bicep
CI/CD
CloudFormation
Datadog
Docker
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
IAM
Jenkins
Kubernetes
Splunk
Terraform
Cybersecurity
Aqua Security
CIS Benchmarks
CWE
Falco
HIPAA
ISO 27001
Kubescape
Kyverno
Least Privilege
Microsoft Sentinel
MITRE ATT&CK
OPA Gatekeeper
OWASP Top 10
PCI DSS
Prisma Cloud
SBOM
SOC 2
Threat Modeling
Trivy
Zero Trust
Open Policy Agent
Apply
Remote • Full-Time • 5+ years exp
PowerShell
Python
SQL
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
Apply
$27k – $72k per year (Estimated) • Remote • Full-Time • 12+ years exp
Go
Java
TypeScript
JavaScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Angular
React.js
DevOps
AWS
Cybersecurity
Sophos
Apply
$27k – $61k per year (Estimated) • Remote • Full-Time • 7+ years exp
PowerShell
SQL
Node JS
JavaScript
Node JS
Commander.js
Cybersecurity
MITRE ATT&CK
osquery
Sophos
Velociraptor
Apply
$98k – $192k per year (Estimated) • Remote • Full-Time • 7+ years exp
JavaScript
TypeScript
AI/ML
Claude
Frontend
Angular
React.js
DevOps
Amazon EC2
Amazon EKS
AWS
AWS Lambda
Kubernetes
Amazon CloudWatch
Amazon ECS
Amazon S3
Cybersecurity
Sophos
Apply
Infosec Engineer 14 days ago
$17k – $44k per year (Estimated) • Remote • Full-Time • 1+ year exp • Bachelor's Degree
Cybersecurity
Sophos
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.