
Security Engineer, Threat Response
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Canada.
• Proactively identify, investigate, and address cyber threats across Sophos and its suite of products.
• Develop detections, automations, reusable skills, and agentic workflows that enhance Internal Detection and Response capabilities.
• Lead complex investigations throughout the incident lifecycle, from initial triage and evidence gathering to containment, recovery, and post-incident analysis.
• Facilitate coordinated responses involving IDR, engineering, product, and business teams.
• Conduct DFIR and endpoint forensics, encompassing log, network, and packet analysis, malware examination, and firewall inquiries.
• Create and refine detections, playbooks, orchestrations, and preventative measures based on incident and threat-hunting insights.
• Develop production-quality automation to alleviate repetitive tasks and enhance consistency.
• Design model-agnostic skills and workflows across approved AI and agent platforms.
• Utilize Claude, Codex, Copilot, and other approved tools for investigations, coding, testing, documentation, and detection engineering.
• Contribute to GitHub by creating branches, submitting and reviewing pull requests, writing tests, addressing feedback, and assisting with controlled deployment.
• Instrument agentic workflows with logs, traces, metrics, evaluation outcomes, and failure indicators.
• Implement safe harness design, least privilege access, scoped tool usage, approval gates, evidence validation, rollback procedures, and human oversight.
• Communicate incidents, risks, decisions, and technical results clearly to engineering and leadership teams.
• Extensive experience in enterprise incident response across endpoint, identity, cloud, network, and product-centric investigations.
• Practical expertise in DFIR, endpoint and firewall forensics, threat hunting, detection engineering, and the analysis of unstructured telemetry.
• Proficiency in writing reliable automation using Python or a similar programming language.
• Experience with APIs and data querying using SQL.
• Familiarity with Git and GitHub engineering practices, including pull requests, code review, testing, and CI/CD principles.
• Hands-on experience with Claude, Codex, or similar coding agents, including context design, task decomposition, and validation of generated outputs.
• Capability to design and write evaluations for agentic workflows and skills.
• Understanding of agent architecture, tool utilization, skill-based design, model portability, and safety controls related to AI or automation.
• Ability to design observability for automated tasks and leverage telemetry to troubleshoot, assess quality, and enhance reliability.
• Strong written and verbal communication skills, sound operational security judgment, and effectiveness in a globally coordinated setting.
• Legal authorization to work in Canada without requiring employer sponsorship.
• Bonus eligibility.
• Comprehensive benefits package.
• Remote-first working model.
• Employee-led diversity and inclusion initiatives.
• Annual charitable and fundraising activities.
• Volunteer days.
• Global employee sustainability efforts.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training.
Reli Group
Second Nature
ASRC Federal
Kyndryl
Get handpicked remote jobs straight to your inbox weekly.