Incident Response Analyst

Posted 2 days ago

This is a fully remote position, open to applicants in Australia.

📋 Description

• Lead the investigative stream for active cyber incidents concerning Managed Detection and Response customers.

• Execute advanced forensic, analytical, and containment operations across various customer environments.

• Investigate, contain, and respond to cyber incidents utilizing Sophos technologies.

• Analyze malware, ransomware, and other prevalent attack types.

• Maintain precise and comprehensive documentation of incident analysis.

• Identify and codify attacker tools, tactics, and procedures.

• Communicate effectively with MDR customers during cyber incidents.

• Collaborate with SophosLabs, Detection Engineering, and Threat Hunting teams to enhance detection logic.

• Work alongside MDR Operations teams on response, remediation guidance, and customer service.

• Produce technical incident reports for MDR customers and MSPs.

• Assist Advisors by validating findings, shaping investigative direction, and preparing technical context for customer communication.

• Operate with moderate autonomy while ensuring technical accuracy, investigative consistency, and high-quality documentation.


⛳️ Requirements

• Over 3 years of experience in conducting cyber security investigations in a systematic manner and investigating threats.

• Familiarity with incident response toolsets, methodologies, and techniques.

• Experience in creating technical documentation and reports.

• Capability to work under high-pressure situations, where response time is crucial to disrupt adversary activity.

• Experience in network and endpoint investigations across macOS, Linux, and Windows.

• Knowledge of IDS, IPS, EDR, and basic malware analysis.

• Basic understanding of at least one of the following: OSQuery, SQL, or KQL.

• Knowledge of the MITRE ATT&CK and Cyber Kill Chain frameworks.

• Willingness to work some weekends and holidays.

• Proficient in using Windows and Linux command and script interpreters.

• Cyber security certifications such as GCIH, CompTIA Security+, or eJPT are preferred.

• Experience with incident response investigations, handling malware, and performing response actions to contain and/or neutralize threats is desired.

• Experience in contacting customers and providing exceptional customer service is a plus.

• Legal authorization to work in Australia without employer sponsorship.


🏝️ Benefits

• Sophos employs a remote-first working model, making remote work the primary option for most employees.

• Employee-led diversity and inclusion networks.

• Annual charity and fundraising initiatives.

• Volunteer days for employees to engage with local communities.

• Global employee sustainability initiatives.

• Global fitness and trivia competitions.

• Global wellbeing days.

• Monthly wellbeing webinars and training to support employee health and wellbeing.

People also viewed

IDS Comercial2 days ago

Gestor de Incidentes

CR flagCosta Rica OnlyFull-timeIncident Response Analyst$1 – $11/hour
ApplyView job
Trend Micro Europe2 days ago

Incident Response Analyst

MX flagMexico, +3 more countriesFull-timeIncident Response Analyst
ApplyView job
Sophos2 days ago

Senior Incident Response Analyst

IN flagIndia OnlyFull-timeIncident Response Analyst
ApplyView job
Reinsurance Group of America, IncorporatedSep 24

Digital Forensics and Incident Response Analyst

IE flagIreland OnlyFull-timeIncident Response Analyst
ApplyView job
Kryptus SASep 21

Mid-Level Incident Response Analyst – DFIR

BR flagBrazil OnlyFull-timeIncident Response Analyst
ApplyView job
SOFTSWISSSep 15

Incident Response Analyst

GE flagGeorgia OnlyFull-timeIncident Response Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers