Sophos
Sophos12d ago
New

Principal Incident Response Engineer 1

CanadaCanadaRemotelead
OtherIncident Response Engineer
0 views0 saves0 applied

Quick Summary

Overview

About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services.

Technical Tools
awsazurecybersecuritylinuxmachine-learning
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
 
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
 
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

As a Principal Incident Response & Readiness Consultant, you will serve as a trusted advisor, leading both proactive and emergency engagements with enterprise customers. Leveraging your comprehensive expertise in cybersecurity, you will help organizations prepare for and respond to cyber incidents, combining strategic readiness consulting with direct guidance through complex cyber incidents.

  • Readiness
    • Conduct comprehensive reviews of incident response plans, identifying gaps and developing tailored strategies to strengthen organizational preparedness.
    • Design and deliver customized incident response playbooks to address specific threats and operational needs.
    • Facilitate training sessions on incident response fundamentals to build customer capabilities.
    • Lead workshops, tabletop exercises, drills, and functional simulations to evaluate and improve readiness.
    • Provide strategic guidance to customers on integrating readiness into broader security programs.
    • Contribute to the development of readiness methodologies and internal knowledge sharing.
    • Incident Response
      • Serve as a subject matter expert in digital forensics and incident response (DFIR).
      • Lead large-scale, complex investigations involving host, network, and cloud artifacts to determine the nature, scope, and root cause of cyber incidents.
      • Collaborate and coordinate with cross-functional incident response teams.
      • Guide containment, remediation, and recovery efforts to secure environments post-incident.
      • Maintain a professional, calming, and authoritative presence during high-pressure incidents.
      • Brief senior leadership and technical teams on findings, risks, and recommendations.
      • Support the development of incident response methodologies and contribute to internal capability building.
      • Participate in a 24x7 emergency response rotation which includes weekends.
  • Comprehensive experience in both readiness and incident response.
  • Strong analytical and problem-solving skills.
  • Ability to lead and mentor cross-functional teams.
  • Excellent communication skills, including executive briefings.
  • Proven ability to manage high-stakes engagements.
  • Experience with forensic tools and techniques (e.g., EDR, log analysis, malware analysis).
  • Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365.
  • Strong understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection and response strategies.
  • Willingness to travel up to 20%, including on short notice, to support on-site customer engagements.
  • 12–15 years of experience in cybersecurity or related fields, with a focus on incident response and readiness.
  • Demonstrated ability to lead high-profile incidents and readiness initiatives.
  • Relevant certifications (e.g., GIAC, CISSP, CISM, or similar) are a plus but not required; proven impact and expertise are primary qualifiers.
  • Location & Eligibility

    Where is the job
    Canada
    Remote within one country
    Who can apply
    CA

    Listing Details

    Posted
    May 1, 2026
    First seen
    May 8, 2026
    Last seen
    May 12, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    46%
    Scored at
    May 8, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Sophos
    Sophos
    lever
    Employees
    3k+
    Founded
    2019
    View company profile
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    SophosPrincipal Incident Response Engineer 1