About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at
www.sophos.com.
Role Summary
Sophos is seeking an experienced and motivated Senior Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.
As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team.
In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.
At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.
The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
What You Will Do
The working week for this role will be Fri, Sat, Sun and Monday working with Tues, Wed and Thursdays off
Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
Provide guidance to customers on best practices following an incident
Lead daily update calls for customers to deliver forensic findings
Deliver concise email updates to customers between update calls
Direct the forensic investigations, identify priorities, and delegate tasks to analysts
Conduct multiple Rapid Response incidents concurrently
Determine TTPs identified by analysts and add them to the threat intel platform
Write clear and concise Executive Summary style reports in a timely manner
Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
What You Will Bring
5+ years of experience leading incident response investigations involving ransomware
Experience leading BEC investigations
Continuously learning and staying informed of the changing threat landscape
Proven track record of successful neutralization and remediation of ransomware threats
Excellent understanding of the Incident Response process
Excellent understanding of cyber risks and able to qualify them to customers
Excellent oral communication skills
Strong written communication skills
Ability to manage time effectively
Able to delegate and prioritize tasks across multiple incidents
Able to excel under stressful circumstances
Occasionally willing to begin work early and/or stay late when warranted for customer engagements
Strong grasp of the MITRE ATT&CK framework
Enjoy mentoring and assisting in the development of junior analysts
A team-player attitude with a willingness to share knowledge
Ability to work some weekends and holidays
Post-secondary education in Cybersecurity, comparable
Desirable:
Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
Experience with SIEM technology (e.g. Splunk, ELK, etc.)
Willingness to work occasional overtime during peak times or holidays
Experience writing SQL queries
Experience writing PowerShell, Python, or Bash scripts