752,626open jobs
45,474companies
109,131added this week
Browse all
Salary
≈ $24k – $58k per year (Estimated)
Location
Remote (India)also open in Canada
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 22, 2026. Sophos scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.

Role Summary

As an MDR Threat Analyst, you will work with enterprise systems, log analysis systems, and endpoint collection systems to facilitate the investigation, identification and neutralization of cyber threats. You will work alongside and contribute to a team of analysts with the objective of providing best in class monitoring, detection and response services.

This role offers an opportunity to grow investigative expertise, work closely with senior analysts, and participate in real-world threat response while helping strengthen the organization’s overall security posture .

What you will do

  • Investigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.
  • Perform structured analysis to determine root cause, attack scope, lateral movement, and potential impact.
  • Support ransomware investigations by analysing attacker activity, credential abuse, persistence mechanisms, and malware behaviour.
  • Deobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity.
  • Conduct proactive threat hunts based on defined hypotheses and emerging threat intelligence.
  • Investigate suspicious authentication activity, privilege escalation, and identity misuse.
  • Perform investigations on both Windows and Linux systems, including log and process analysis.
  • Correlate data across multiple sources, including EDR, SIEM, cloud logs, and identity platforms.
  • Document investigative findings clearly and provide actionable remediation guidance to clients.
  • Collaborate with senior analysts during high-severity or complex incidents.
  • Contribute to detection tuning and improvement of response playbooks based on investigation outcomes.
  • Participate in a rotational schedule supporting a 24x7x365 MDR environment.

What you will bring

  • 3-5 years of experience in a SOC, MDR, Incident Response, or related cybersecurity operations role.
  • Experience investigating endpoint and network security alerts using EDR and SIEM platforms.
  • Working knowledge of ransomware attack patterns and common intrusion techniques.
  • Hands-on experience investigating Linux and Windows systems.
  • Experience analysing obfuscated scripts, malware behaviour, and performing deobfuscation to identify malicious activity.
  • Familiarity with adversary tactics and techniques, and practical exposure to the MITRE ATT&CK framework.
  • Experience analysing Windows Event Logs, Linux logs, and Active Directory fundamentals.
  • Basic understanding of cloud and identity security investigations, including suspicious authentication activity and privileged account misuse.
  • Ability to analyse network traffic, including TCP/IP, DNS, and HTTP/S.
  • Scripting knowledge, including PowerShell; Python or other languages is mandatory.
  • Strong documentation skills and attention to investigative detail.
  • Security certifications such as Security+, CySA+, GCIH, or equivalent are a plus. Bachelor’s degree in Information Technology, Computer Science, or related field, or equivalent professional experience.
  • Strong analytical and troubleshooting skills.
  • Ability to manage multiple investigations in a fast-paced environment.
  • Clear written and verbal communication skills.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
752,626 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $21k – $48k per year (Estimated) • In office • Full-Time • 2+ years exp • Noida
DevOps
Azure
Cybersecurity
SentinelOne
Microsoft Defender
GDPR
Management
ITIL
Apply
≈ $33k – $74k per year (Estimated) • In office • Full-Time • 13+ years exp • Bachelor's Degree • Bengaluru
Python
Java
Management
Agile
Scrum
Apply
≈ $34k – $76k per year (Estimated) • In office • 5+ years exp • Hyderabad
Python
AI/ML
Copilot
ChatGPT
AI Agents
Agentic Workflows
DevOps
Splunk
Azure
AWS
Docker
Kubernetes
Cybersecurity
Qualys Cloud Platform
ISO 27001
OWASP Top 10
PCI DSS
Fortify
Sonatype Nexus IQ
Analytics
Power BI
Apply
≈ $33k – $75k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
GCP
Azure
AWS
IAM
DNS
DHCP
VPN
BGP
OSPF
MPLS
Cybersecurity
Zero Trust
Least Privilege
SIEM
DLP
Apply
≈ $28k – $63k per year (Estimated) • In office • 5+ years exp • Hyderabad
DevOps
Terraform
Ansible
GCP
Azure
AWS
Kubernetes
CentOS Stream
IAM
Linux
VPN
Cybersecurity
FortiGate
HashiCorp Vault
ISO 27001
Wiz
Zero Trust
Microsoft Entra ID
LDAP
PKI
Cryptography
Vault
Apply
≈ $76k – $157k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Irving • Austin
Python
AI/ML
Machine Learning
DevOps
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
OWASP Top 10
Trend Micro
SIEM
Apply
≈ $109k – $238k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Irving • Austin
Python
Rust
C++
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
Platform Engineering
Cybersecurity
MITRE ATT&CK
OWASP Top 10
Trend Micro
SIEM
Apply
$66k – $79k per year • Hybrid • London
DevOps
Ansible
Ubuntu
Linux
Windows
Apply
$34k – $36k per year • In office • Lomagna
Python
SQL
AI/ML
Prompt Engineering
LLM
Machine Learning
Analytics
Informatica
Apply
≈ $35k – $83k per year (Estimated) • In office • TS/SCI • Full-Time • Associate's Degree • Longmont
DevOps
Red Hat
VMWare
AWS
Kubernetes
Linux
DNS
Cybersecurity
Active Directory
LDAP
Apply
Threat Analyst 1 3 days ago
≈ $64k – $137k per year (Estimated) • Remote (Canada) • Full-Time • 2+ years exp
SQL
PowerShell
DevOps
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
≈ $107k – $218k per year (Estimated) • Remote (Canada) • Full-Time • 10+ years exp
Python
SQL
PowerShell
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
≈ $33k – $75k per year (Estimated) • Remote (India) • Full-Time • 7+ years exp
JavaScript
SQL
PowerShell
Node JS
Node JS
Commander.js
Cybersecurity
Velociraptor
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Senior Threat Analyst 1 month ago
≈ $102k – $209k per year (Estimated) • Remote (Canada) • Full-Time • 5+ years exp • Bachelor's Degree
SQL
PowerShell
DevOps
Red Hat
Debian
Ubuntu
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
≈ $84k – $161k per year (Estimated) • Remote (United Kingdom) • Full-Time • 5+ years exp
Python
SQL
PowerShell
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
See all jobs
This is one of many
752,626 more open roles from verified company boards, updated every day.