Senior Incident Response Consultant – Rapid Response

Posted 6hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Incident Response Consultant leading ransomware investigations for Sophos, a global cybersecurity provider. Directing forensic response, customer communications, remediation, and MITRE ATT&CK reporting.

Responsibilities:

  • Work Fri, Sat, Sun, and Monday, with Tuesday, Wednesday, and Thursday off
  • Lead kickoff calls with customers to understand their situation and identify initial response actions to contain threats
  • Provide customers with post-incident best-practice guidance
  • Lead daily customer update calls and deliver forensic findings
  • Send concise email updates between calls
  • Direct forensic investigations, identify priorities, and delegate tasks to analysts
  • Conduct multiple Rapid Response incidents concurrently
  • Determine analyst-identified TTPs and add them to the threat intelligence platform
  • Write timely, clear, and concise executive-summary-style reports
  • Lead basic-to-moderate complexity projects contributing to development of the Sophos Rapid Response service
  • Provide daily handover notes to teams in different time zones or when incident responsibility transfers
  • Ensure appropriate actions are taken by the team and customer to neutralize threats
  • Conduct root cause analysis, including determining whether data exfiltration occurred when evidence is available
  • Produce reports containing timelines mapped to the MITRE ATT&CK framework and remediation guidance
  • Lead a team of Incident Response Consultants and communicate complex technical information to executive stakeholders

Requirements:

  • 5+ years of experience leading incident response investigations involving ransomware
  • Experience leading BEC investigations
  • Continuously learning and staying informed of the changing threat landscape
  • Proven track record of successful neutralization and remediation of ransomware threats
  • Excellent understanding of the Incident Response process
  • Excellent understanding of cyber risks and ability to qualify them to customers
  • Excellent oral communication skills
  • Strong written communication skills
  • Ability to manage time effectively
  • Ability to delegate and prioritize tasks across multiple incidents
  • Ability to excel under stressful circumstances
  • Willingness to begin work early and/or stay late when warranted for customer engagements
  • Strong grasp of the MITRE ATT&CK framework
  • Enjoy mentoring and assisting in the development of junior analysts
  • Team-player attitude with willingness to share knowledge
  • Ability to work some weekends and holidays
  • Post-secondary education in Cybersecurity, comparable
  • Legal authorization to work in Romania without requiring employer sponsorship
  • Desirable: Cybersecurity certifications such as CISSP or GCFA
  • Desirable: Experience with SIEM technology such as Splunk or ELK
  • Desirable: Willingness to work occasional overtime
  • Desirable: Experience writing SQL queries
  • Desirable: Experience writing PowerShell, Python, or Bash scripts

Benefits:

  • Remote-first working model, with remote work as the primary option for most employees
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training
  • Equality of opportunity and support with recruitment and selection process adjustments