Salary
≈ $56k – $135k per year (Estimated)
Location
Remote (United Kingdom)also open in Canada, India
Seniority
Middle · 2+ years exp
Employment
Full-Time
Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 25, 2026. Sophos scores B on the Alion truth index.
Overview
Company
Impact
Profile match
Sophos is a global leader in cybersecurity, providing businesses and individuals with a comprehensive range of solutions to protect against a wide range of cyber threats. Our products include endpoint protection, network security, and cloud security. Sophos is committed to providing our customers with the highest level of security and protection, and we are always innovating to stay ahead of the latest threats.
Role Summary
As a Threat Analyst - Tier II on our Managed Detection and Response (MDR) team, you will provide best-in-class monitoring, detection, and response services to proactively defend customer environments before attacks prevail. You will work alongside and contribute to a team of cyber threat hunters, incident response analysts, engineers, and ethical hackers by using enterprise, log analysis and endpoint collection systems to facilitate investigations, identification, and neutralization of cyber threats.
What You Will Do
- Investigate and analyze logs and security-related events via Sophos tooling
- Handle escalations from Tier I Threat Analysts - guide / advise on investigation handling
- Onboard and train new Threat Analysts
- Create cases, track and follow up with clients through threat neutralization
- Communicate and document findings to various customer audiences including technical and executive teams
- Follow up with customers through to issue resolution and drive continuous improvement by providing detailed recommendations to minimize risk in customer environments
- Acknowledge and satisfy inbound customer requests and interact with customers through various mediums (Email, Phone, Ticket)
- Collaborate and assist with core security and threat response teams
- Actively research emerging Indicators of Compromise/Attack, exploits and vulnerabilities
- Conduct threat hunting to identify potential threats throughout the MDR customer base
- Participate in Security Operations process improvement and creation
- Obtain metrics for reporting on threat trends, intelligence analysis and situational awareness
What You Will Bring
- 2+ years of experience working in a SOC environment or computer security team in an IT environment
- Endpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experience
- Experience with threat hunting
- Experience administering and supporting Windows OS (workstations and server) and one of the following: Apple or Linux-based operating systems (RedHat, Debian, Ubuntu, OS X)
- Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc.
- Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
- Strong understanding of Windows event log analysis
- Working knowledge of incident response procedures
- Passion for all things related to information technology and cybersecurity
- Natural curiosity and ability to learn new skills quickly
- Excellent troubleshooting and analytical skills, with proven ability to think outside the box
- Customer service-oriented with strong written and verbal communication skills
- Must thrive within a team environment as well as on an individual basis
- Innovative mindset and driven to contribute to a team providing a best-in-class cybersecurity service
- Bachelors in Information Technology, Computer Science or a related field; or relevant commensurate work experience
- Willingness to work outside of standard business days including weekends and holidays - our MDR service is 24x7x365 (Hours are standard business hours)
- Knowledge of MITRE ATT&CK framework
- Experience with SQL query construction
- Experience with OSQuery Programming and scripting skills - proficient knowledge of PowerShell
- Experience with enterprise information security data management - SIEM
- Advanced Cyber Security certifications
Essential:
Desirable
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
791,964 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Security
Similar stack
Same company
In your city
$100k – $150k per year • Remote (United States) • 6+ years exp • PhD
Python
Databases
Oracle
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
FedRAMP
Zero Trust
Threat Modeling
SIEM
Apply
$145k – $165k per year • Remote (United States) • 6+ years exp • Bachelor's Degree
AI/ML
LLM
DevOps
CI/CD
Cybersecurity
OWASP Top 10
Management
Agile
Apply
$100k – $130k per year • Remote (United States) • 6+ years exp • Bachelor's Degree
Python
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Zero Trust
SIEM
Apply
$100k – $150k per year • Remote (United States) • 6+ years exp • PhD
Python
Java
C++
Databases
KDB+
Apply
Application Security Engineer
1 month ago
≈ $34k – $77k per year (Estimated) • Remote (India) • 5+ years exp • India
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
IAM
Cybersecurity
Snyk
SonarQube
Checkmarx
OWASP Top 10
Zero Trust
Fortify
Apply
Системный администратор Linux
1 day ago
≈ $16k – $30k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Saint Petersburg
DevOps
Debian
Ubuntu
KVM
QEMU
Linux
Windows
Astra Linux
DNS
DHCP
Apply
Technical Specialist
7 hours ago
In office
Java
Java
Spring Framework
Databases
Apache Kafka
Apache Ignite
DevOps
Ansible
Red Hat
OpenShift
Azure DevOps
Prometheus
Azure
CI/CD
Git
Grafana
Configuration Management
Linux
Unix
Management
Agile
Scrum
ITIL
Apply
Senior Technical Lead
1 day ago
In office
Java
Java
Spring Framework
Databases
Apache Kafka
Apache Ignite
DevOps
Ansible
Red Hat
OpenShift
Azure DevOps
Prometheus
Azure
CI/CD
Git
Grafana
Configuration Management
Linux
Unix
Management
Agile
Scrum
ITIL
Apply
Системный инженер ПАК Скала^Р
1 day ago
≈ $27k – $56k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Moscow
Java
SQL
Java
Apache Tomcat
Databases
PostgreSQL
DevOps
VMWare
etcd
Prometheus
Docker
Kubernetes
Grafana
QEMU
Linux
Cybersecurity
Tcpdump
Apply
Django Developer
1 day ago
$10k – $20k per year (net) • In office • 2+ years exp • Tashkent
Python
Python
Django
Celery
Django REST Framework
Databases
PostgreSQL
Redis
AI/ML
LLM
DevOps
Rest API
GCP
WebSockets
Azure
CI/CD
Git
AWS
Docker
Nginx
Linux
QA
Swagger
Pytest
Apply
Incident Response Engineer 2
1 day ago
≈ $58k – $141k per year (Estimated) • Remote (United Kingdom) • Full-Time • 2+ years exp
SQL
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Threat Analyst 1
3 days ago
≈ $64k – $137k per year (Estimated) • Remote (Canada) • Full-Time • 2+ years exp
SQL
PowerShell
DevOps
Linux
Windows
TCP/IP
Cybersecurity
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
Threat Analyst 2
4 days ago
≈ $24k – $58k per year (Estimated) • Remote (India) • Full-Time • 3+ years exp • Bachelor's Degree
Python
PowerShell
DevOps
Linux
Windows
TCP/IP
DNS
Cybersecurity
MITRE ATT&CK
Active Directory
SIEM
Apply
Senior Incident Response Consultant 2
1 month ago
≈ $107k – $218k per year (Estimated) • Remote (Canada) • Full-Time • 10+ years exp
Python
SQL
PowerShell
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
MITRE ATT&CK
Sophos
SIEM
Apply
Manager, Incident Response
1 month ago
≈ $33k – $75k per year (Estimated) • Remote (India) • Full-Time • 7+ years exp
JavaScript
SQL
PowerShell
Node JS
Node JS
Commander.js
Cybersecurity
Velociraptor
MITRE ATT&CK
osquery
Sophos
SIEM
Apply
This is one of many
791,964 more open roles from verified company boards, updated every day.

