
Incident Response Engineer – Level 2
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United Kingdom.
• Conduct sophisticated investigative and forensic analysis across endpoints, network logs, and cloud telemetry.
• Implement containment and response actions to mitigate active threats as instructed by Incident Advisors or Senior Analysts.
• Confirm indicators of compromise and correlate alerts, artifacts, and telemetry to ascertain the scope and underlying cause.
• Maintain precise and thorough engagement documentation, including trailheads, timelines, and playbooks.
• Offer guidance and mentorship to junior IR and SOC analysts.
• Compile technical findings and summaries for customer updates and post-incident reports.
• Identify and communicate detection or response gaps noted during investigations.
• Engage in shift handovers, debriefs, and post-incident reviews.
• Ensure accurate tracking of time and activities.
• Provide support to Managed Detection and Response customers within Sophos's Critical Incident Response Team.
• A minimum of 2 years of experience in incident response, MDR, SOC, or security operations roles.
• Strong technical proficiency in endpoint forensics, log analysis, and prevalent attack techniques.
• Experience in investigating malware, credential theft, ransomware, or similar threats.
• Capability to correlate alerts and telemetry to establish incident scope and root cause.
• Excellent written and verbal communication skills for documenting findings and contributing to customer updates.
• Experience in mentoring or guiding junior analysts.
• Ability to perform effectively in high-pressure, time-sensitive incident environments.
• Willingness to work some weekends and holidays as part of a rotation.
• Practical experience with EDR, SIEM, and forensic collection tools.
• Familiarity with OSQuery, SQL, or KQL.
• Knowledge of MITRE ATT&CK and incident response frameworks.
• Relevant industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent.
• Experience in contributing to playbooks, detection tuning, or service improvement initiatives.
• Legal authorization to work in the United Kingdom without employer sponsorship.
• Remote-first working model, with remote work as the primary option for most employees.
• Employee-led diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days.
• Global employee sustainability initiatives.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training.
• Recruitment and selection process adjustments available for applicants who need them.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.