
MDR Team Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in India.
• Oversee daily MDR operations, managing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure reliable service delivery.
• Direct and evaluate incident investigations, confirming findings, assessing business impact, recommending response actions, and ensuring effective escalation management.
• Act as a primary coordination point during customer and internal escalations, delivering clear updates, risk assessments, recommendations, and resolution strategies.
• Mentor and develop MDR analysts through case evaluations, constructive feedback, skills enhancement, and performance oversight.
• Conduct quality assessments of investigations, customer interactions, documentation, and calls to promote operational excellence and ongoing improvement.
• Analyze operational metrics and dashboards to uncover trends, risks, capacity limitations, and opportunities to enhance service quality, efficiency, and customer satisfaction.
• Create and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational preparedness.
• Offer technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities.
• Direct response efforts during major security incidents, ensuring effective coordination, decision-making, and ownership until resolution.
• Stay informed about threat actor tactics, techniques, and procedures (TTPs), utilizing threat intelligence to bolster investigations, detections, and response capabilities.
• Collaborate with Engineering, Labs, and Content teams to enhance detection quality, minimize false positives, and resolve recurring investigation issues.
• Up to 12 years of overall work experience.
• 5+ years of experience in cybersecurity, including at least 2-3 years in leadership, mentoring, or coordination roles for analysts in a SOC, MDR, Incident Response, or similar setting.
• Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent practical experience.
• Practical experience in security operations, including threat detection, incident investigation, and response.
• Strong knowledge of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms.
• Familiarity with threat hunting methodologies and the MITRE ATT&CK framework is preferred.
• Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence.
• Strong technical skills in Windows environments, including host artifacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus.
• Solid understanding of networking fundamentals including TCP/IP, routing, switching, and traffic analysis.
• Experience with SIEM platforms and enterprise security data management; database querying skills are beneficial.
• Proficiency in PowerShell and Python for automation and investigation support.
• Strong analytical, troubleshooting, and decision-making abilities, with the capacity to prioritize effectively in high-pressure environments.
• Excellent written and verbal communication skills, capable of producing clear reports, case summaries, operational updates, and executive-ready communications.
• Experience in conducting quality reviews and providing actionable feedback that enhances investigation outcomes and analyst performance.
• Proven capability to develop team skills through coaching, onboarding, training, and knowledge sharing.
• Strong stakeholder management and customer-facing skills, able to explain technical findings, risks, and recommendations to both technical and non-technical audiences.
• Advanced cybersecurity certifications are preferred but not mandatory.
• Sophos operates under a remote-first working model.
• Employee-led diversity and inclusion networks that foster community and provide education and advocacy.
• Annual charity and fundraising initiatives alongside volunteer days for employees to support local communities.
• Global employee sustainability initiatives aimed at reducing our environmental impact.
• Global fitness and trivia competitions to keep our bodies and minds sharp.
• Global wellbeing days for employees to relax and recharge.
• Monthly wellbeing webinars and training to support employee health and wellbeing.
Rasmussen University
Weekday (YC W21)
Jobs for Humanity
Teaching Finance
Get handpicked remote jobs straight to your inbox weekly.