
Threat Analyst – MDR
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in India.
• Manage escalations from level I Threat Analysts, providing guidance and advice on investigation processes.
• Onboard and train new Threat Analysts.
• Engage in the enhancement and development of Security Operations processes.
• Deliver detection and response services for security incidents and cyber threats.
• Oversee security log management and monitoring activities.
• Maintain metrics related to information security.
• Support core security and threat response teams.
• Generate reports related to MDR services.
• Create cases for clients.
• Monitor and follow up with clients throughout the threat neutralization process.
• Communicate with clients through various channels.
• Conduct active research on recent Indicators of Compromise/Attack, exploits, and vulnerabilities.
• Gather metrics for reporting on threat trends, intelligence analysis, and situational awareness.
• 2-4 years of experience in a SOC environment or as part of a computer security team within an IT setting.
• Required experience in endpoint and network security; familiarity with IDS, IPS, EDR, ATP, and malware defenses and monitoring.
• Threat hunting experience is preferred.
• Understanding of common adversary tactics and techniques, such as obfuscation, persistence, and defense evasion.
• Knowledge of the Mitre ATT&CK framework is preferred.
• Practical knowledge of incident response procedures.
• Preferred experience in constructing SQL queries.
• Familiarity with OSQuery is a plus.
• Experience in administering and supporting Windows OS (both workstations and servers) and one of the following: Apple or Linux-based operating systems (e.g., XP, Windows 7, 2003, 2008, OS X).
• Basic understanding of network traffic analysis, including TCP/IP, routing, switching, and protocols.
• Strong knowledge of Windows event log analysis.
• Experience with enterprise information security data management; SIEM experience is a plus.
• Proficiency in scripting languages such as KQL, PowerShell, or Python.
• Excellent analytical thinking and troubleshooting abilities.
• Strong skills in documentation and communication.
• Advanced Cyber Security certifications are preferred but not mandatory.
• A Bachelor’s degree in Information Technology, Computer Science, or a related field, or equivalent relevant work experience.
• Willingness to work outside standard business hours, including weekends and holidays, as our Managed Detection and Response operates 24/7/365.
• Ability to work well in both team settings and independently.
• Sophos adopts a remote-first working model.
• Our culture emphasizes innovation and creativity, complemented by a strong sense of fun and teamwork.
• Employee-led diversity and inclusion networks that foster community and provide education and advocacy.
• Annual charity and fundraising initiatives, along with volunteer days for employees to engage with local communities.
• Global initiatives focused on sustainability to minimize our environmental impact.
• Worldwide fitness and trivia competitions to keep our bodies and minds active.
• Global wellbeing days for employees to unwind and recharge.
• Monthly webinars and training sessions focused on supporting employee health and wellbeing.
Manulife
Agile Defense
DYOPATH
Get handpicked remote jobs straight to your inbox weekly.