
Senior Incident Response Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in India.
• Lead the execution of investigations into active cyber incidents for MDR clients and MSPs.
• Utilize Sophos technologies to investigate, contain, and respond to cyber incidents.
• Conduct advanced analyses of incident responses to identify initial access, persistence, and lateral movement.
• Provide mentorship to incident response analysts and MDR operations analysts through technical guidance, review, and escalation support.
• Assist customers and MSPs via phone calls and meetings regarding cyber incidents.
• Offer recommendations to contain, neutralize, and remediate threats.
• Analyze malware, ransomware, and other prevalent attack types.
• Ensure the maintenance of accurate and detailed documentation of incident analysis.
• Collaborate with SophosLabs, Detection Engineering, Threat Hunting, and MDR Operations teams.
• Contribute, as appropriate, to Sophos blogs, social media, and other platforms regarding adversary TTPs and IOCs.
• Assess technologies and processes to enhance incident response capabilities.
• Generate technical incident reports as post-incident deliverables for MDR clients and MSPs.
• Over 4 years of experience in conducting cybersecurity investigations and threat analysis, or at least 2 years in incident response engagements.
• Knowledge of network architecture and IT infrastructure.
• Experience in creating technical documentation and reports for clients.
• Capability to perform under high-pressure situations where response time is critical.
• Investigation experience across macOS, Linux, and Windows environments.
• Familiarity with IDS, IPS, EDR, and fundamental malware analysis.
• Proficiency in at least one of OSQuery, SQL, or KQL.
• Experience applying frameworks such as MITRE Attack and Cyber Kill Chain.
• Willingness to work on some weekends and holidays.
• Knowledge of Windows and Linux command-line and scripting interpreters.
• Legal authorization to work in India without requiring employer sponsorship.
• Advanced cybersecurity certifications such as GCFE/GCFA, CompTIA CySA+, or OSCP are preferred.
• Prior experience engaging with customers and providing exceptional customer service is preferred.
• Cybersecurity publications are a plus.
• Remote-first working model.
• Employee-led diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days.
• Global employee sustainability initiatives.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training.
• Recruitment adjustments to support applicants with disabilities or other needs.
Sophos
IDS Comercial
Trend Micro Europe
Reinsurance Group of America, Incorporated
Get handpicked remote jobs straight to your inbox weekly.