Incident Response Analyst

Posted 15hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Incident Response Analyst leading forensic investigations and containment for Sophos’s managed detection and response customers. Collaborating with security teams to improve threat detection and incident reporting.

Responsibilities:

  • Lead the investigative stream of active cyber incidents for Managed Detection and Response customers
  • Perform advanced forensic, analytical, and containment tasks across diverse customer environments
  • Investigate, contain, and respond to cyber incidents using Sophos technologies
  • Analyze malware, ransomware, and other common attack types
  • Maintain accurate and detailed documentation of incident analysis
  • Recognize and codify attacker tools, tactics, and procedures
  • Communicate clearly with MDR customers during cyber incidents
  • Collaborate with SophosLabs, Detection Engineering, and Threat Hunting teams to improve detection logic
  • Work with MDR Operations teams on response, remediation guidance, and customer service
  • Create technical incident reports for MDR customers and MSPs
  • Support Advisors by validating findings, shaping investigative direction, and preparing technical context for customer communication
  • Operate with moderate autonomy while ensuring technical accuracy, investigative consistency, and high-quality documentation

Requirements:

  • 3+ years of experience conducting cyber security investigations in a methodical manner and investigating threats
  • Knowledge of incident response toolsets, methodologies, and techniques
  • Experience creating technical documentation and technical reports
  • Ability to work under high-pressure situations, when response time matters, to disrupt adversary activity
  • Network and endpoint investigation experience across macOS, Linux, and Windows
  • Experience with IDS, IPS, EDR, and basic malware analysis
  • Basic understanding of at least one of: OSQuery, SQL, and KQL
  • Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks
  • Ability to work some weekends and holidays
  • Experience with Windows and Linux command and script interpreters
  • Cyber security certifications such as GCIH, CompTIA Security+, or eJPT (desired)
  • Experience with incident response investigations, handling malware, and performing response actions to contain and/or neutralize threats (desired)
  • Experience calling customers and providing excellent customer service (desired)
  • Legal authorization to work in Australia without employer sponsorship

Benefits:

  • Sophos operates a remote-first working model, making remote work the primary option for most employees
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days for employees to support local communities
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training to support employee health and wellbeing