Incident Response Engineer – Level 2

Posted 1 day ago

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Conduct sophisticated investigative and forensic analysis across endpoints, network logs, and cloud telemetry.

• Implement containment and response actions to mitigate active threats as instructed by Incident Advisors or Senior Analysts.

• Confirm indicators of compromise and correlate alerts, artifacts, and telemetry to ascertain the scope and underlying cause.

• Maintain precise and thorough engagement documentation, including trailheads, timelines, and playbooks.

• Offer guidance and mentorship to junior IR and SOC analysts.

• Compile technical findings and summaries for customer updates and post-incident reports.

• Identify and communicate detection or response gaps noted during investigations.

• Engage in shift handovers, debriefs, and post-incident reviews.

• Ensure accurate tracking of time and activities.

• Provide support to Managed Detection and Response customers within Sophos's Critical Incident Response Team.


⛳️ Requirements

• A minimum of 2 years of experience in incident response, MDR, SOC, or security operations roles.

• Strong technical proficiency in endpoint forensics, log analysis, and prevalent attack techniques.

• Experience in investigating malware, credential theft, ransomware, or similar threats.

• Capability to correlate alerts and telemetry to establish incident scope and root cause.

• Excellent written and verbal communication skills for documenting findings and contributing to customer updates.

• Experience in mentoring or guiding junior analysts.

• Ability to perform effectively in high-pressure, time-sensitive incident environments.

• Willingness to work some weekends and holidays as part of a rotation.

• Practical experience with EDR, SIEM, and forensic collection tools.

• Familiarity with OSQuery, SQL, or KQL.

• Knowledge of MITRE ATT&CK and incident response frameworks.

• Relevant industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent.

• Experience in contributing to playbooks, detection tuning, or service improvement initiatives.

• Legal authorization to work in the United Kingdom without employer sponsorship.


🏝️ Benefits

• Remote-first working model, with remote work as the primary option for most employees.

• Employee-led diversity and inclusion networks.

• Annual charity and fundraising initiatives.

• Volunteer days.

• Global employee sustainability initiatives.

• Global fitness and trivia competitions.

• Global wellbeing days.

• Monthly wellbeing webinars and training.

• Recruitment and selection process adjustments available for applicants who need them.

People also viewed

Cloudiax14 hours ago

Information Security, Compliance & IKS Manager – ISO 27001

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco16 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Cisco1 day ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Skylight1 day ago

Senior Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers