
Senior Incident Response Consultant – Rapid Response
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Romania.
• Work on Friday, Saturday, Sunday, and Monday, enjoying Tuesday, Wednesday, and Thursday off.
• Facilitate kickoff calls with clients to assess their circumstances and determine initial response strategies to mitigate threats.
• Offer customers post-incident best-practice recommendations.
• Conduct daily update calls with customers and present forensic findings.
• Provide succinct email updates between calls.
• Oversee forensic investigations, establish priorities, and assign tasks to analysts.
• Manage multiple Rapid Response incidents simultaneously.
• Identify TTPs recognized by analysts and incorporate them into the threat intelligence platform.
• Compose timely, clear, and concise executive-summary reports.
• Lead projects of basic to moderate complexity that contribute to the enhancement of the Sophos Rapid Response service.
• Deliver daily handover notes to teams operating in different time zones or when transferring incident responsibilities.
• Ensure that the team and customers take appropriate measures to neutralize threats.
• Perform root cause analyses, including assessing data exfiltration when evidence is available.
• Generate reports featuring timelines aligned with the MITRE ATT&CK framework and provide remediation guidance.
• Supervise a team of Incident Response Consultants and convey intricate technical information to executive stakeholders.
• Over 5 years of experience in leading incident response investigations, particularly involving ransomware.
• Expertise in conducting BEC investigations.
• Commitment to continuous learning and staying updated on the evolving threat landscape.
• Proven history of successful neutralization and remediation of ransomware threats.
• Strong understanding of the Incident Response process.
• In-depth knowledge of cyber risks and the ability to articulate them to clients.
• Exceptional oral communication capabilities.
• Strong written communication skills.
• Effective time management skills.
• Proficient in delegating and prioritizing tasks across multiple incidents.
• Ability to perform well under pressure.
• Willingness to start work early or stay late when necessary for client engagements.
• Solid understanding of the MITRE ATT&CK framework.
• Passion for mentoring and aiding in the development of junior analysts.
• Team-oriented mindset with a readiness to share knowledge.
• Availability to work some weekends and holidays.
• Post-secondary education in Cybersecurity or a related field.
• Legal authorization to work in Romania without employer sponsorship.
• Desirable: Cybersecurity certifications such as CISSP or GCFA.
• Desirable: Experience with SIEM technologies like Splunk or ELK.
• Desirable: Willingness to occasionally work overtime.
• Desirable: Experience in writing SQL queries.
• Desirable: Proficiency in writing scripts in PowerShell, Python, or Bash.
• Remote-first working model, making remote work the primary option for most employees.
• Employee-led diversity and inclusion initiatives.
• Annual charity and fundraising activities.
• Volunteer days available.
• Global employee sustainability efforts.
• International fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training sessions.
• Commitment to equality of opportunity and support for adjustments in the recruitment and selection process.
BCD Travel
Nuvitek
Nuvitek
Nuvitek
Get handpicked remote jobs straight to your inbox weekly.