Senior Incident Response Engineer
Quick Summary
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services.
Sophos is seeking an experienced and motivated Incident Response Consultant to join our Incident Response (IR) service. The Sophos IR team is an elite group of incident responders that are engaged by organizations worldwide to respond to and neutralize cyber threats. Specializing in industry-standard forensic tools and Sophos technologies, the team provides comprehensive investigations, response actions, remediation guidance, and root cause analysis to combat a wide range of cybersecurity incidents.
As a Senior Incident Response Consultant on the Sophos IR team, you will be responsible for spearheading incident response engagements for customers who have experienced a cybersecurity attack. In this role, you will lead a team of Incident Response Consultants, running customer-facing calls, providing detailed written updates via email, and determining the priorities of the investigation, delegating tasks accordingly to your team.
In this role, you will be accountable for ensuring that the appropriate actions have been taken by both your team and the customer to effectively neutralize the threat. Additionally, you will be tasked with conducting a thorough root cause analysis to determine the origin of the incident, including identifying whether any data exfiltration occurred, provided the necessary evidence is available.
At the culmination of each engagement, you will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident and provide remediation guidance.
The ideal candidate for this role will possess extensive experience leading incident response efforts, a deep understanding of cybersecurity threats and mitigation strategies, and the ability to communicate complex technical information to executive-level stakeholders in a clear and concise manner.
- Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
- Provide guidance to customers on best practices following an incident
- Lead daily update calls for customers to deliver forensic findings
- Deliver concise email updates to customers between update calls
- Direct the forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple Rapid Response incidents concurrently
- Determine TTPs identified by analysts and add them to the threat intel platform
- Write clear and concise Executive Summary style reports in a timely manner
- Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
- Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
- 5+ years of experience leading incident response investigations involving ransomware
- Experience leading BEC investigations
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of successful neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process
- Excellent understanding of cyber risks and able to qualify them to customers
- Excellent oral communication skills
- Strong written communication skills
- Ability to manage time effectively
- Able to delegate and prioritize tasks across multiple incidents
- Able to excel under stressful circumstances
- Occasionally willing to begin work early and/or stay late when warranted for customer engagements
- Strong grasp of the MITRE ATT&CK framework
- Enjoy mentoring and assisting in the development of junior analysts
- A team-player attitude with a willingness to share knowledge
- Ability to work on weekends and holidays
- Post-secondary education in Cybersecurity, comparable
Location & Eligibility
Listing Details
- Posted
- August 5, 2026
- First seen
- August 5, 2026
- Last seen
- August 5, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- August 5, 2026
Signal breakdown
Please let Sophos know you found this job on Jobera.
3 other jobs at Sophos
View all →Explore open roles at Sophos.
Similar Incident Response Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.