Salary
≈ $24k – $58k per year (Estimated)
Location
Remote (India)also open in Canada
Seniority
Middle · 3+ years exp
Employment
Full-Time
Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 22, 2026. Sophos scores B on the Alion truth index.
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.
Role Summary
As an MDR Threat Analyst, you will work with enterprise systems, log analysis systems, and endpoint collection systems to facilitate the investigation, identification and neutralization of cyber threats. You will work alongside and contribute to a team of analysts with the objective of providing best in class monitoring, detection and response services.
This role offers an opportunity to grow investigative expertise, work closely with senior analysts, and participate in real-world threat response while helping strengthen the organization’s overall security posture .
What you will do
- Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.
- Perform structured analysis to determine root cause, attack scope, lateral movement, and potential impact.
- Support ransomware investigations by analysing attacker activity, credential abuse, persistence mechanisms, and malware behaviour.
- Deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity.
- Conduct proactive threat hunts based on defined hypotheses and emerging threat intelligence.
- Investigate suspicious authentication activity, privilege escalation, and identity misuse.
- Perform investigations on both Windows and Linux systems, including log and process analysis.
- Correlate data across multiple sources, including EDR, SIEM, cloud logs, and identity platforms.
- Document investigative findings clearly and provide actionable remediation guidance to clients.
- Collaborate with senior analysts during high-severity or complex incidents.
- Contribute to detection tuning and improvement of response playbooks based on investigation outcomes.
- Participate in a rotational schedule supporting a 24x7x365 MDR environment.
What you will bring
- 3-5 years of experience in a SOC, MDR, Incident Response, or related cybersecurity operations role.
- Experience investigating endpoint and network security alerts using EDR and SIEM platforms.
- Working knowledge of ransomware attack patterns and common intrusion techniques.
- Hands-on experience investigating Linux and Windows systems.
- Experience analysing obfuscated scripts, malware behaviour, and performing deobfuscation to identify malicious activity.
- Familiarity with adversary tactics and techniques, and practical exposure to the MITRE ATT&CK framework.
- Experience analysing Windows Event Logs, Linux logs, and Active Directory fundamentals.
- Basic understanding of cloud and identity security investigations, including suspicious authentication activity and privileged account misuse.
- Ability to analyse network traffic, including TCP/IP, DNS, and HTTP/S.
- Scripting knowledge, including PowerShell; Python or other languages is mandatory.
- Strong documentation skills and attention to investigative detail.
- Security certifications such as Security+, CySA+, GCIH, or equivalent are a plus. Bachelor’s degree in Information Technology, Computer Science, or related field, or equivalent professional experience.
- Strong analytical and troubleshooting skills.
- Ability to manage multiple investigations in a fast-paced environment.
- Clear written and verbal communication skills.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
752,626 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Security
Similar stack
Same company
In your city
≈ $21k – $48k per year (Estimated) • In office • Full-Time • 2+ years exp • Noida
DevOps
Azure
Cybersecurity
SentinelOne
Microsoft Defender
GDPR
Management
ITIL
Apply
≈ $33k – $74k per year (Estimated) • In office • Full-Time • 13+ years exp • Bachelor's Degree • Bengaluru
Python
Java
Management
Agile
Scrum
Apply
Technical Specialist-Cybersecurity
17 days ago
≈ $34k – $76k per year (Estimated) • In office • 5+ years exp • Hyderabad
Python
AI/ML
Copilot
ChatGPT
AI Agents
Agentic Workflows
DevOps
Splunk
Azure
AWS
Docker
Kubernetes
Cybersecurity
Qualys Cloud Platform
ISO 27001
OWASP Top 10
PCI DSS
Fortify
Sonatype Nexus IQ
Analytics
Power BI
Apply
Sr. Network Security Engineer with Juniper SRX
10 days ago
≈ $33k – $75k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
GCP
Azure
AWS
IAM
DNS
DHCP
VPN
BGP
OSPF
MPLS
Cybersecurity
Zero Trust
Least Privilege
SIEM
DLP
Apply
Cloud Security Engineer
3 months ago
≈ $28k – $63k per year (Estimated) • In office • 5+ years exp • Hyderabad
DevOps
Terraform
Ansible
GCP
Azure
AWS
Kubernetes
CentOS Stream
IAM
Linux
VPN
Cybersecurity
FortiGate
HashiCorp Vault
ISO 27001
Wiz
Zero Trust
Microsoft Entra ID
LDAP
PKI
Cryptography
Vault
Apply
≈ $76k – $157k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Irving • Austin
Python
AI/ML
Machine Learning
DevOps
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
OWASP Top 10
Trend Micro
SIEM
Apply
≈ $109k – $238k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Irving • Austin
Python
Rust
C++
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
Platform Engineering
Cybersecurity
MITRE ATT&CK
OWASP Top 10
Trend Micro
SIEM
Apply
Linux Desktop Support Engineer
3 days ago
$66k – $79k per year • Hybrid • London
DevOps
Ansible
Ubuntu
Linux
Windows
Apply
AI & Data Specialist Junior
2 days ago
$34k – $36k per year • In office • Lomagna
Python
SQL
AI/ML
Prompt Engineering
LLM
Machine Learning
Analytics
Informatica
Apply
Technical Services Operations Administrator
2 days ago
≈ $35k – $83k per year (Estimated) • In office • TS/SCI • Full-Time • Associate's Degree • Longmont
DevOps
Red Hat
VMWare
AWS
Kubernetes
Linux
DNS
Cybersecurity
Active Directory
LDAP
Apply
Threat Analyst 1
3 days ago
≈ $64k – $137k per year (Estimated) • Remote (Canada) • Full-Time • 2+ years exp
SQL
PowerShell
DevOps
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Senior Incident Response Consultant 2
1 month ago
≈ $107k – $218k per year (Estimated) • Remote (Canada) • Full-Time • 10+ years exp
Python
SQL
PowerShell
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
Manager, Incident Response
1 month ago
≈ $33k – $75k per year (Estimated) • Remote (India) • Full-Time • 7+ years exp
JavaScript
SQL
PowerShell
Node JS
Node JS
Commander.js
Cybersecurity
Velociraptor
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Senior Threat Analyst
1 month ago
≈ $102k – $209k per year (Estimated) • Remote (Canada) • Full-Time • 5+ years exp • Bachelor's Degree
SQL
PowerShell
DevOps
Red Hat
Debian
Ubuntu
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Senior Incident Response Consultant, Rapid Response
2 months ago
≈ $84k – $161k per year (Estimated) • Remote (United Kingdom) • Full-Time • 5+ years exp
Python
SQL
PowerShell
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
This is one of many
752,626 more open roles from verified company boards, updated every day.

