{"id":1117396,"url":"https://alion.io/job/sophos-threat-analyst-1","title":"Threat Analyst 1","company":{"id":1926,"name":"Sophos","domain":"sophos.com","url":"https://alion.io/company/sophos","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":79,"open_postings":8,"ghost_share":0,"stale_share":0.625,"repost_share":0,"time_to_fill_p50_days":83,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["CA"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":64000,"max_usd":137000,"period":"year","method":"role_seniority_country_cell","sample_n":9},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"osquery","optional":false},{"name":"PowerShell","optional":false},{"name":"SIEM","optional":false},{"name":"Sophos","optional":false},{"name":"SQL","optional":false},{"name":"TCP/IP","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-22T15:49:38Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-25T18:59:21Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Role Summary\nAs a Threat Analyst 1 on our Managed Threat Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail. You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats. Shift: 8-5pm ET\nWhat You Will Do\nInvestigate and analyze logs and security-related events via Sophos tooling\nIdentify and respond to cyber threats occurring within customer environments\nCommunicate and document findings to various customer audiences including technical and executive teams\nFollow up with customers through to issue resolution and drive continuous improvement by providing detailed recommendations to minimize risk in customer environments \nAcknowledge and satisfy inbound customer requests and interact with customers through various mediums\nCollaborate and assist with core security and threat response teams\nActively research emerging Indicators of Compromise/Attack, exploits and vulnerabilities with the intent of operationalizing findings to better protect our customers\nWhat You Will Bring\nWillingness to work outside of standard business hours, including weekends and holidays - our MDR service is 24x7x365\nExcellent troubleshooting and analytical skills, with proven ability to think outside the box\nCustomer service-oriented with strong written and verbal communication skills\nMust thrive within a team environment as well as on an individual basis\nPassion for all things related to information technology and cybersecurity\nNatural curiosity and ability to learn new skills quickly\nInnovative mindset and driven to contribute to a team providing a best-in-class cybersecurity service\nMinimum 2+ years of experience working in a SOC environment or computer security team in an IT environment\nExperience with threat hunting\nExperience with endpoint and network security monitoring \nExperience administering and supporting Windows OS (both workstations and server) and one of the following: Apple or Linux-based operating systems (e.g. XP, Windows 7, 2003, 2008, OS X)\nKnowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc.\nKnowledge of Mitre ATT&CK framework\nKnowledge of incident response procedures\nBasic understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.\nBasic understanding of Windows event log analysis\nA plus if you have:\nExperience with SQL query construction \nExperience with OSQuery \nExperience with enterprise information security data management - SIEM experience \nProgramming and scripting skills - proficient knowledge of Powershell","description_format":"text","description_chars":2871,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Canada","iso":"CA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Managed Security"],"lifecycle":[{"event":"open","at":"2026-09-22T17:03:47Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":83,"reasons":["conf:1","velocity","win:early","comp:junior"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/sophos-threat-analyst-1","json_url":"https://alion.io/job/sophos-threat-analyst-1.json","meta":{"generated_at":"2026-09-25T23:44:32Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"assistant","counted_by":"address","units_charged":1,"used_today":149,"day_limit":2000,"remaining_today":1851,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}