
Senior Incident Response Consultant
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Canada.
• Facilitate initial kickoff calls with clients to assess their circumstances and determine initial response strategies for threat containment.
• Provide guidance to clients on best practices following an incident.
• Conduct daily update calls with clients and present forensic findings.
• Send succinct email updates in between calls.
• Oversee forensic investigations, set priorities, and assign tasks to analysts.
• Manage multiple incidents simultaneously.
• Identify TTPs recognized by analysts and incorporate them into the threat intelligence platform.
• Compose timely Executive Summary-style reports.
• Contribute to developing the Sophos DFIR service on projects ranging from basic to moderate complexity.
• Provide daily handover notes for teams in various time zones or when transitioning incident responsibilities.
• Lead incident response efforts and teams for clients facing cybersecurity threats.
• Collaborate with legal counsel and cyber insurance providers as required.
• Ensure that suitable actions are taken to neutralize threats.
• Perform root cause analysis, including assessing potential data exfiltration incidents.
• Generate reports detailing key-event timelines aligned with the MITRE ATT&CK framework and provide remediation guidance.
• Over 10 years of experience in leading incident response investigations related to ransomware, network breaches, malicious insiders, and web applications and database services.
• Proven experience in leading BEC investigations.
• Extensive digital forensic analysis experience with data from AWS, Microsoft Azure, and GCP.
• Commitment to ongoing learning and staying updated on the evolving threat landscape.
• Established history of neutralizing and remediating ransomware threats.
• Strong understanding of the Incident Response process and cyber risks.
• Excellent verbal communication and proficient written communication skills.
• Effective time management capabilities.
• Skill in delegating and prioritizing tasks across multiple incidents.
• Ability to perform well under pressure.
• Willingness to start work early and/or extend hours as needed.
• Solid understanding of the MITRE ATT&CK framework.
• Ability to mentor and share knowledge.
• Availability to work some weekends and holidays.
• Cybersecurity certifications such as CISSP, GCFA, or similar credentials are advantageous.
• Familiarity with SIEM technologies like Splunk or ELK is preferred.
• Willingness to work occasional overtime during peak periods or holidays is preferred.
• Experience in writing SQL queries is preferred.
• Experience in writing scripts using PowerShell, Python, or Bash is preferred.
• Eligibility for bonuses.
• Comprehensive benefits package.
• Remote-first working environment.
• Employee-led networks focused on diversity and inclusion.
• Annual charity and fundraising initiatives.
• Days dedicated to volunteering.
• Global initiatives for employee sustainability.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly webinars and training sessions on wellbeing.
BCD Travel
Nuvitek
Nuvitek
Nuvitek
Get handpicked remote jobs straight to your inbox weekly.