370,096open jobs
9,485companies
49,010added this week
Browse all
Location
Remote (Romania)
Seniority
Senior · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

As a Senior Threat Analyst - Tier I on our Managed Detection and Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail. You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats.

What You Will Do

    • Monitor, investigate, and respond to alerts generated by the Sophos security stack (including EDR/XDR capabilities)
    • Lead and mentor Tier I Analysts through escalated cases, ensuring thorough and accurate investigation practices.
    • Perform end-to-end analysis on suspicious activity to assess scope, impact, and risk
    • Identify and respond to cyber threats across customer environments using approved playbooks and tooling
    • Accurately document findings, investigative steps, and outcomes in the MDR case management platform
    • Conduct threat hunting to identify potential threats throughout the MDR customer base
    • Investigate phishing emails, suspicious binaries, and behavioral anomalies
    • Support detection tuning by identifying recurring false positives and suggesting improvements
    • Stay informed on threat actor behaviors, MITRE ATT&CK techniques, and Sophos threat research updates
    • Proactively research emerging IOCs, active exploits, and vulnerabilities to stay ahead of evolving threats
    • Contribute to internal knowledge bases, documentation, and continuous improvement initiatives
    • Participate in shift rotations and ensure timely, detailed handovers between global teams
    • Provide detection and response support for active security incidents
    • Manage case workflows: create cases, track progress, and follow up with clients until resolution
    • Engage with clients via chat, phone, and tickets as part of case handling
    • Assist with developing and refining Security Operations processes, playbooks, and tooling feedback

What You Will Bring

    Essential

    • 3+ years of hands-on experience in a Security Operations Center (SOC), Managed Detection and Response (MDR) environment, or cybersecurity-focused IT role
    • Proficient in the use of endpoint and network security tools (e.g., EDR, IDS/IPS, malware detection platforms) with the ability to validate and triage complex alerts
    • Working knowledge of Windows operating systems (both workstation and server), with additional experience in Linux (Ubuntu, Debian, RedHat) or macOS environments
    • Ability to interpret and analyze Windows event logs and other telemetry data
    • Understanding of core network concepts including TCP/IP, protocols, routing, and traffic analysis
    • Demonstrated experience contributing to real-time incident response efforts and threat investigations
    • Exposure to threat hunting methodologies and an understanding of attacker behavior and patterns
    • Experience handling active threats, including containment, mitigation, and recovery efforts during security incidents
    • Familiar with techniques such as persistence, privilege escalation, lateral movement, and defense evasion, and able to identify these in real-world environments
    • Familiarity with common incident response workflows and security operations processes
    • Strong analytical thinking and troubleshooting skills, with attention to detail in investigations and case documentation
    • Excellent communication skills, with the ability to clearly explain findings to both technical and non-technical audiences
    • Customer-first mindset with professionalism and a focus on service excellence
    • Must thrive within a team environment as well as on an individual basis
    • Natural curiosity and willingness to learn in a fast-paced, ever-changing threat landscape
    • A passion for cybersecurity, continuous improvement, and staying current on threat trends
      • Bachelor's degree in information technology, Computer Science, Cybersecurity or related field, or equivalent practical experience
      • Ability to communicate in English
        • Willingness to participate in shift work including nights, weekends and holidays (our MDR service is 24x7x365)
        • Desirable

          • Familiarity with the MITRE ATT&CK framework and its application in detection and response
          • Experience working with SIEM platforms and managing enterprise security telemetry
          • Ability to write and interpret SQL queries for data analysis and investigation
          • Experience with OSQuery and scripting skills, particularly in PowerShell
          • Relevant and practical cybersecurity certifications (e.g., GSEC, GCIA, GCIH, PEN-200, Security Blue Team L1, TCM Academy SOC L1, or similar)
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
370,096 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$21k – $35k per year • In office • Moscow
Bash
Python
Databases
MySQL
PostgreSQL
DevOps
Ansible
Debian
Grafana
Proxmox VE
Ubuntu
Zabbix
Apply
$38k – $96k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Madrid
DevOps
Ansible
CI/CD
Configuration Management
GitLab
GitLab CI
HPC
Red Hat
Ubuntu
Apply
Robot SWE 8 hours ago
$100k – $200k per year • Equity 0.2–1.2% • In office • Full-Time • Bachelor's Degree • Los Angeles
Bash
C++
Python
AI/ML
Computer Vision
Human-in-the-Loop
DevOps
Docker
Git
Ubuntu
Robotics
Autonomous Navigation
Motion Planning
Obstacle Avoidance
ROS2
Sensor Fusion
SLAM
Teleoperation
Apply
Senior ML Engineer 8 hours ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
System Administrator 8 hours ago
$101k – $196k per year (Estimated) • In office • Full-Time • 6+ years exp • Associate's Degree • Huntsville
DevOps
Red Hat
Apply
Remote • Full-Time • 5+ years exp
PowerShell
Python
SQL
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
Apply
$27k – $72k per year (Estimated) • Remote • Full-Time • 12+ years exp
Go
Java
TypeScript
JavaScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Angular
React.js
DevOps
AWS
Cybersecurity
Sophos
Apply
$27k – $61k per year (Estimated) • Remote • Full-Time • 7+ years exp
PowerShell
SQL
Node JS
JavaScript
Node JS
Commander.js
Cybersecurity
MITRE ATT&CK
osquery
Sophos
Velociraptor
Apply
$98k – $192k per year (Estimated) • Remote • Full-Time • 7+ years exp
JavaScript
TypeScript
AI/ML
Claude
Frontend
Angular
React.js
DevOps
Amazon EC2
Amazon EKS
AWS
AWS Lambda
Kubernetes
Amazon CloudWatch
Amazon ECS
Amazon S3
Cybersecurity
Sophos
Apply
Infosec Engineer 15 days ago
$17k – $44k per year (Estimated) • Remote • Full-Time • 1+ year exp • Bachelor's Degree
Cybersecurity
Sophos
Apply
See all jobs
This is one of many
370,096 more open roles from verified company boards, updated every day.