{"id":1114205,"url":"https://alion.io/job/sophos-threat-analyst-2-2","title":"Threat Analyst 2","company":{"id":1926,"name":"Sophos","domain":"sophos.com","url":"https://alion.io/company/sophos","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":79,"open_postings":8,"ghost_share":0,"stale_share":0.625,"repost_share":0,"time_to_fill_p50_days":83,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["IN"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":24000,"max_usd":58000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":337},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"DNS","optional":false},{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"TCP/IP","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-22T12:55:32Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-26T01:25:33Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Role Summary\nAs an MDR Threat Analyst, you will work with enterprise systems, log analysis systems, and endpoint collection systems to facilitate the investigation, identification and neutralization of cyber threats. You will work alongside and contribute to a team of analysts with the objective of providing best in class monitoring, detection and response services.\nThis role offers an opportunity to grow investigative expertise, work closely with senior analysts, and participate in real-world threat response while helping strengthen the organization’s overall security posture .\nWhat you will do\nInvestigate escalated security alerts and incidents across endpoint, network, cloud, and identity environments.\nPerform structured analysis to determine root cause, attack scope, lateral movement, and potential impact.\nSupport ransomware investigations by analysing attacker activity, credential abuse, persistence mechanisms, and malware behaviour.\nDeobfuscate suspicious scripts, malware samples, and other indicators to identify malicious activity.\nConduct proactive threat hunts based on defined hypotheses and emerging threat intelligence.\nInvestigate suspicious authentication activity, privilege escalation, and identity misuse.\nPerform investigations on both Windows and Linux systems, including log and process analysis. \nCorrelate data across multiple sources, including EDR, SIEM, cloud logs, and identity platforms.\nDocument investigative findings clearly and provide actionable remediation guidance to clients. \nCollaborate with senior analysts during high-severity or complex incidents. \nContribute to detection tuning and improvement of response playbooks based on investigation outcomes. \nParticipate in a rotational schedule supporting a 24x7x365 MDR environment. \nWhat you will bring\n3-5 years of experience in a SOC, MDR, Incident Response, or related cybersecurity operations role.\nExperience investigating endpoint and network security alerts using EDR and SIEM platforms.\nWorking knowledge of ransomware attack patterns and common intrusion techniques.\nHands-on experience investigating Linux and Windows systems.\nExperience analysing obfuscated scripts, malware behaviour, and performing deobfuscation to identify malicious activity.\nFamiliarity with adversary tactics and techniques, and practical exposure to the MITRE ATT&CK framework.\nExperience analysing Windows Event Logs, Linux logs, and Active Directory fundamentals.\nBasic understanding of cloud and identity security investigations, including suspicious authentication activity and privileged account misuse.\nAbility to analyse network traffic, including TCP/IP, DNS, and HTTP/S.\nScripting knowledge, including PowerShell; Python or other languages is mandatory.\nStrong documentation skills and attention to investigative detail.\nSecurity certifications such as Security+, CySA+, GCIH, or equivalent are a plus. Bachelor’s degree in Information Technology, Computer Science, or related field, or equivalent professional experience.\nStrong analytical and troubleshooting skills.\nAbility to manage multiple investigations in a fast-paced environment.\nClear written and verbal communication skills.","description_format":"text","description_chars":3182,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Managed Security"],"lifecycle":[{"event":"open","at":"2026-09-22T14:09:37Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":83,"reasons":["conf:1","velocity","win:early"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/sophos-threat-analyst-2-2","json_url":"https://alion.io/job/sophos-threat-analyst-2-2.json","meta":{"generated_at":"2026-09-26T03:42:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3963,"day_limit":5000,"remaining_today":1037,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}