Senior Incident Response Consultant – Rapid Response
Posted 6hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Incident Response Consultant leading ransomware investigations for Sophos, a global cybersecurity provider. Directing forensic response, customer communications, remediation, and MITRE ATT&CK reporting.
Responsibilities:
- Work Fri, Sat, Sun, and Monday, with Tuesday, Wednesday, and Thursday off
- Lead kickoff calls with customers to understand their situation and identify initial response actions to contain threats
- Provide customers with post-incident best-practice guidance
- Lead daily customer update calls and deliver forensic findings
- Send concise email updates between calls
- Direct forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple Rapid Response incidents concurrently
- Determine analyst-identified TTPs and add them to the threat intelligence platform
- Write timely, clear, and concise executive-summary-style reports
- Lead basic-to-moderate complexity projects contributing to development of the Sophos Rapid Response service
- Provide daily handover notes to teams in different time zones or when incident responsibility transfers
- Ensure appropriate actions are taken by the team and customer to neutralize threats
- Conduct root cause analysis, including determining whether data exfiltration occurred when evidence is available
- Produce reports containing timelines mapped to the MITRE ATT&CK framework and remediation guidance
- Lead a team of Incident Response Consultants and communicate complex technical information to executive stakeholders
Requirements:
- 5+ years of experience leading incident response investigations involving ransomware
- Experience leading BEC investigations
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of successful neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process
- Excellent understanding of cyber risks and ability to qualify them to customers
- Excellent oral communication skills
- Strong written communication skills
- Ability to manage time effectively
- Ability to delegate and prioritize tasks across multiple incidents
- Ability to excel under stressful circumstances
- Willingness to begin work early and/or stay late when warranted for customer engagements
- Strong grasp of the MITRE ATT&CK framework
- Enjoy mentoring and assisting in the development of junior analysts
- Team-player attitude with willingness to share knowledge
- Ability to work some weekends and holidays
- Post-secondary education in Cybersecurity, comparable
- Legal authorization to work in Romania without requiring employer sponsorship
- Desirable: Cybersecurity certifications such as CISSP or GCFA
- Desirable: Experience with SIEM technology such as Splunk or ELK
- Desirable: Willingness to work occasional overtime
- Desirable: Experience writing SQL queries
- Desirable: Experience writing PowerShell, Python, or Bash scripts
Benefits:
- Remote-first working model, with remote work as the primary option for most employees
- Employee-led diversity and inclusion networks
- Annual charity and fundraising initiatives
- Volunteer days
- Global employee sustainability initiatives
- Global fitness and trivia competitions
- Global wellbeing days
- Monthly wellbeing webinars and training
- Equality of opportunity and support with recruitment and selection process adjustments















