
Senior Incident Response Consultant, Rapid Response
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in United Kingdom.
• This position requires working from Friday to Monday, with Tuesday, Wednesday, and Thursday off.
• Facilitate kickoff calls with clients to assess their situations and determine initial response actions to mitigate threats.
• Offer customers expert advice on best practices following an incident.
• Conduct daily update calls with clients to present forensic findings.
• Send clear email updates to clients between scheduled update calls.
• Oversee forensic investigations, set priorities, and assign tasks to analysts.
• Manage multiple Rapid Response incidents simultaneously.
• Identify TTPs recognized by analysts and incorporate them into the threat intelligence platform.
• Compose clear and concise Executive Summary reports promptly.
• Accountable for basic to moderately complex projects that aid in the advancement of the Sophos Rapid Response service.
• Provide daily handover notes to teams in different time zones or when transferring incident responsibility to another Incident Lead.
• Minimum of 5 years of experience leading incident response investigations related to ransomware.
• Experience in leading Business Email Compromise (BEC) investigations.
• Commitment to continuous learning and staying up-to-date with the evolving threat landscape.
• Demonstrated success in neutralizing and remediating ransomware threats.
• Strong understanding of the Incident Response process.
• Comprehensive knowledge of cyber risks and the ability to communicate them effectively to clients.
• Exceptional oral communication skills.
• Strong written communication abilities.
• Proficient in time management.
• Capability to delegate and prioritize tasks across multiple incidents.
• Ability to perform well under pressure.
• Willingness to occasionally start work early or stay late for customer engagements as needed.
• Solid understanding of the MITRE ATT&CK framework.
• Passion for mentoring and supporting the growth of junior analysts.
• Team-oriented mindset with a readiness to share knowledge.
• Flexibility to work some weekends and holidays.
• Post-secondary education in Cybersecurity or a related field.
• **Desirable:**
• Cybersecurity certifications (e.g., CISSP, GCFA, or similar) are advantageous.
• Familiarity with SIEM technology (e.g., Splunk, ELK, etc.).
• Willingness to work occasional overtime during peak periods or holidays.
• Experience in writing SQL queries.
• Proficiency in scripting languages such as PowerShell, Python, or Bash.
• Sophos follows a remote-first work model, making remote work the primary option for most employees.
• Our team fosters innovation and creativity, all while maintaining a fun and spirited atmosphere.
• Employee-led diversity and inclusion networks that cultivate community and provide education and advocacy.
• Annual charity and fundraising events, along with volunteer days, enabling employees to support local communities.
• Global employee sustainability initiatives aimed at reducing our environmental impact.
• Engaging global fitness and trivia competitions to keep our bodies and minds active.
• Global wellbeing days for employees to unwind and recharge.
• Monthly wellbeing webinars and training sessions to promote employee health and wellness.
Sprout Social, Inc.
Premier Inc.
Devoir Software Solutions
Get handpicked remote jobs straight to your inbox weekly.