Senior Incident Response Engineer
- Role
- Security
- Experience
- Senior
- Company size
- Enterprise
Open to IN only. Set where you work from to check your eligibility.
No BS summary
Senior incident response consultant/engineer for cybersecurity attack investigations. Needs extensive experience leading IR engagements, forensic tooling, threat mitigation, executive stakeholder communication, and legal authorization to work in India without sponsorship.
Core skills
Required skills
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K.
Role Summary Sophos is seeking an experienced and motivated Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.
As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team. In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available. At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance. The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
What you'll do
- Spearhead incident response engagements for customers who have experienced a cybersecurity attack.
- Lead a team of Incident Response Consultants.
- Run customer-facing calls.
- Provide detailed written updates via email.
- Determine investigation priorities and delegate tasks to the team.
- Ensure appropriate actions have been taken by both the team and customer to effectively neutralize the threat.
- Conduct thorough root cause analysis to determine the origin of the incident.
- Identify whether any data exfiltration occurred, provided the necessary evidence is available.
- Produce an executive summary-style report at the end of each engagement.
- Include a timeline of key events mapped to the MITRE ATT&CK framework in the report.
- Provide remediation guidance to stakeholders.
What they require
- Experienced and motivated Incident Response Consultant.
- Specializing in industry-standard forensic tools and Sophos technologies.
- Extensive experience leading incident response efforts.
- Deep understanding of cybersecurity threats and mitigation strategies.
- Ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
- Applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship.
Benefits
- Sophos operates a remote-first working model, making remote work the primary option for most employees.
- Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit.
- Employee-led diversity and inclusion networks that build community and provide education and advocacy.
- Annual charity and fundraising initiatives and volunteer days for employees to support local communities.
- Global employee sustainability initiatives to reduce our environmental footprint.
- Global fitness and trivia competitions to keep our bodies and minds sharp.
- Global wellbeing days for employees to relax and recharge.
- Monthly wellbeing webinars and training to support employee health and wellbeing.
What people say about this company
3.8/ 5