Senior Incident Response Analyst, MDR

atSophosRemoteCA flagCanadaFull-timeUncategorizedSeniorC$131k – C$219k/year

Posted 3 days ago

This is a fully remote position, open to applicants in Canada.

📋 Description

• Assist Managed Detection and Response (MDR) clients within the Critical Incident Response Team (CIRT)

• Lead intricate investigations involving sophisticated adversaries, multi-vector intrusions, or cross-environment compromises

• Act as the primary Incident Advisor or appointed Commander for high-severity incidents

• Direct and coordinate investigative, forensic, and containment efforts among multiple analysts

• Establish engagement strategies, investigative priorities, and containment methods based on risk and impact

• Validate and consolidate technical findings into clear, actionable recommendations for customers and internal stakeholders

• Offer technical mentorship and oversight to IR and SOC analysts

• Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to confirm detections and address visibility gaps

• Lead or contribute to post-incident reviews, enhancing playbooks, tools, and response workflows

• Keep accurate records of time and activities to support operational visibility and capacity planning


⛳️ Requirements

• Over 5 years of experience in incident response, MDR, or cybersecurity investigations, including leadership of complex incidents

• Advanced knowledge in endpoint and network forensics, log analysis, and adversary tactics

• Strong comprehension of enterprise network architecture and IT infrastructure

• Proven capacity to lead investigations, validate findings, and devise effective containment strategies

• Experience in conveying technical findings to clients, including senior and executive stakeholders

• Demonstrated mentorship and leadership capabilities across incident response teams

• Ability to function effectively under high-pressure, time-sensitive scenarios

• Willingness to work occasional weekends and holidays as part of a rotation

• Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent) — preferred

• Experience serving as Incident Advisor or Commander during critical engagements — preferred

• Contributions to publications, presentations, or recognized efforts within the cybersecurity community — preferred

• Experience influencing detection strategies, tooling enhancements, or service design — preferred

• Strong customer-facing skills with experience briefing executives during incidents — preferred

• Legal authorization to work in Canada without requiring employer sponsorship


🏝️ Benefits

• Bonus eligibility

• Comprehensive benefits package

• Remote-first working model

• Employee-led diversity and inclusion networks

• Annual charity and fundraising initiatives

• Volunteer days

• Global employee sustainability initiatives

• Global fitness and trivia competitions

• Global wellbeing days

• Monthly wellbeing webinars and training

• Equality of opportunity and recruitment adjustments where needed

People also viewed

Hempel A/S11 hours ago

Coating Advisor – Marine

US flagUnited States OnlyFull-timeUncategorized
ApplyView job
Hempel A/S11 hours ago

Coating Advisor – Marine

US flagFlorida, +1 more stateFull-timeUncategorized
ApplyView job
RTX11 hours ago

Specialist, Enterprise Strategy

US flagConnecticut OnlyFull-timeUncategorized$86.8k – $165.2k/year
ApplyView job
FLYACTS • Venture Studio für erfahrene Unternehmer12 hours ago

Entrepreneur in Residence – B2B SaaS

DE flagGermany OnlyFull-timeUncategorized
ApplyView job
ElevenLabs15 hours ago

Deployment Strategist

MX flagMexico OnlyFull-timeUncategorized
ApplyView job
Horizon Blue ABA16 hours ago

BCBA, LBA

US flagMaryland OnlyFull-timeUncategorized$60k – $100k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers