
Senior Incident Response Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in India.
• Facilitate kickoff meetings with clients to assess their circumstances and identify initial actions to mitigate threats.
• Offer expert advice to clients on best practices for incident response.
• Conduct daily update calls with customers and present forensic findings.
• Provide succinct email updates between meetings.
• Oversee forensic investigations, prioritize tasks, and assign responsibilities to analysts.
• Manage multiple Rapid Response incidents simultaneously.
• Analyze analysts’ identified TTPs and incorporate them into the threat intelligence platform.
• Compose timely, clear, and concise executive summary reports.
• Lead projects of basic to moderate complexity that contribute to the development of the Sophos Rapid Response service.
• Deliver daily handover notes to teams in varying time zones or when transitioning incident responsibilities.
• Ensure that response actions effectively neutralize threats and conduct root-cause analysis, including any potential data exfiltration.
• Generate final reports that include event timelines aligned with MITRE ATT&CK and remediation advice.
• Mentor and support junior analysts.
• Over 5 years of experience leading incident response investigations, particularly in ransomware cases.
• Experience in leading Business Email Compromise (BEC) investigations.
• Commitment to ongoing learning and awareness of the evolving threat landscape.
• Demonstrated success in neutralizing and remediating ransomware threats.
• Strong understanding of the incident response process.
• In-depth knowledge of cyber risks and the ability to assess them for clients.
• Exceptional oral communication abilities.
• Strong written communication skills.
• Capability to manage time efficiently.
• Proficient in delegating and prioritizing tasks across multiple incidents.
• Ability to perform effectively under pressure.
• Openness to starting work early or staying late when necessary for client engagements.
• Solid understanding of the MITRE ATT&CK framework.
• Willingness to mentor junior analysts.
• Team-oriented mindset and readiness to share knowledge.
• Availability to work on weekends and holidays.
• Post-secondary education in Cybersecurity or a related field.
• Cybersecurity certifications such as CISSP or GCFA are advantageous.
• Familiarity with SIEM technologies like Splunk or ELK is preferred.
• Willingness to occasionally work overtime during peak times or holidays.
• Experience in writing SQL queries is preferred.
• Proficiency in writing scripts in PowerShell, Python, or Bash is desirable.
• Remote-first working environment.
• Employee-driven diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days.
• Global employee sustainability initiatives.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training sessions.
• Commitment to equal opportunity and adjustments in the recruitment process for applicants.
Zscaler
Viatris
ActBlue
AlphaSense
Get handpicked remote jobs straight to your inbox weekly.