Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Role Summary
Sophos is seeking an experienced and motivated Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.
As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team.
In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.
At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.
The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
What you will do
- Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
- Provide guidance to customers on best practices following an incident
- Lead daily update calls for customers to deliver forensic findings
- Deliver concise email updates to customers between update calls
- Direct the forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple Rapid Response incidents concurrently
- Determine TTPs identified by analysts and add them to the threat intel platform
- Write clear and concise Executive Summary style reports in a timely manner
- Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
- Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
What you will bring
- 5+ years of experience leading incident response investigations involving ransomware
- Experience leading BEC (Business Email Compromise) investigations
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of successful neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process
- Excellent understanding of cyber risks and able to qualify them to customers
- Excellent oral communication skills
- Strong written communication skills
- Ability to manage time effectively
- Able to delegate and prioritize tasks across multiple incidents
- Able to excel under stressful circumstances
- Occasionally willing to begin work early and/or stay late when warranted for customer engagements
- Strong grasp of the MITRE ATT&CK framework
- Enjoy mentoring and assisting in the development of junior analysts
- A team-player attitude with a willingness to share knowledge
- Ability to work on weekends and holidays
- Post-secondary education in Cybersecurity, comparable
- Desirable:
- Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
- Experience with SIEM technology (e.g. Splunk, ELK, etc.)
- Willingness to work occasional overtime during peak times or holidays
- Experience writing SQL queries
- Experience writing PowerShell, Python, or Bash scripts
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Sophos
Explore Top Companies in this Space
Clariticloudinc
Permitting Software
GenPeach AI
Artificial Intelligence / Generative AI / Enterprise Software
Censys
Cybersecurity / Attack Surface Management / Threat Intelligence / SaaS
Creative Chaos
Custom Software Development
Sophos
View Company ProfileSophos (operating at sophos.com) is a security software and hardware company engineered for cybersecurity. Founded in Not specified by Not specified and headquartered in Oxford, Sophos takes a prevention-first approach to security by stopping threats earlier — blocking ransomware, phishing, and credential-based attacks before they become business-disrupting events. Under the hood, Sophos is powered by agentic AI and elite human expertise, detecting, investigating, and neutralizing threats. This allows more than 40,000 customers worldwide to defeat cyberattacks and achieve superior cybersecurity outcomes. Backed by Not specified.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.



