
Incident Response Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Australia.
• Lead the investigative stream for active cyber incidents concerning Managed Detection and Response customers.
• Execute advanced forensic, analytical, and containment operations across various customer environments.
• Investigate, contain, and respond to cyber incidents utilizing Sophos technologies.
• Analyze malware, ransomware, and other prevalent attack types.
• Maintain precise and comprehensive documentation of incident analysis.
• Identify and codify attacker tools, tactics, and procedures.
• Communicate effectively with MDR customers during cyber incidents.
• Collaborate with SophosLabs, Detection Engineering, and Threat Hunting teams to enhance detection logic.
• Work alongside MDR Operations teams on response, remediation guidance, and customer service.
• Produce technical incident reports for MDR customers and MSPs.
• Assist Advisors by validating findings, shaping investigative direction, and preparing technical context for customer communication.
• Operate with moderate autonomy while ensuring technical accuracy, investigative consistency, and high-quality documentation.
• Over 3 years of experience in conducting cyber security investigations in a systematic manner and investigating threats.
• Familiarity with incident response toolsets, methodologies, and techniques.
• Experience in creating technical documentation and reports.
• Capability to work under high-pressure situations, where response time is crucial to disrupt adversary activity.
• Experience in network and endpoint investigations across macOS, Linux, and Windows.
• Knowledge of IDS, IPS, EDR, and basic malware analysis.
• Basic understanding of at least one of the following: OSQuery, SQL, or KQL.
• Knowledge of the MITRE ATT&CK and Cyber Kill Chain frameworks.
• Willingness to work some weekends and holidays.
• Proficient in using Windows and Linux command and script interpreters.
• Cyber security certifications such as GCIH, CompTIA Security+, or eJPT are preferred.
• Experience with incident response investigations, handling malware, and performing response actions to contain and/or neutralize threats is desired.
• Experience in contacting customers and providing exceptional customer service is a plus.
• Legal authorization to work in Australia without employer sponsorship.
• Sophos employs a remote-first working model, making remote work the primary option for most employees.
• Employee-led diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days for employees to engage with local communities.
• Global employee sustainability initiatives.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training to support employee health and wellbeing.
IDS Comercial
Trend Micro Europe
Sophos
Reinsurance Group of America, Incorporated
Get handpicked remote jobs straight to your inbox weekly.