Senior Threat Analyst
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Threat Analyst delivering threat monitoring, detection, and response for Sophos, a global cybersecurity provider. Leading investigations, threat hunts, and incident response for customer environments.
Responsibilities:
- Monitor, investigate, and respond to alerts generated by the Sophos security stack, including EDR/XDR capabilities
- Escalate and lead complex and high-severity investigations through resolution
- Lead technical responses to major security incidents, coordinating containment and remediation with customers and internal teams
- Mentor and coach Tier I and Tier II Analysts and quality-review case work
- Analyze suspicious activity to assess scope, impact, and risk
- Identify and respond to cyber threats across customer environments using approved playbooks and tooling
- Document findings, investigative steps, and outcomes in the MDR case management platform
- Plan and lead hypothesis-driven threat hunts informed by threat intelligence and adversary behavior
- Investigate phishing emails, suspicious binaries, and behavioral anomalies
- Improve detections by addressing false positives, coverage gaps, and detection logic
- Research threat actor behaviors, MITRE ATT&CK techniques, emerging IOCs, active exploits, and vulnerabilities
- Author and maintain playbooks, knowledge base articles, and documentation
- Participate in shift rotations and provide detailed handovers between global teams
- Manage case workflows and follow up with clients until resolution
- Engage with clients in English and Japanese via chat, phone, and tickets
- Contribute to Security Operations processes and provide tooling feedback
Requirements:
- 5+ years of hands-on experience in a Security Operations Center (SOC), Managed Detection and Response (MDR) environment, or cybersecurity-focused IT role
- Proven experience leading incident response efforts, including containment, mitigation, and recovery during active security incidents
- Strong experience with endpoint and network security tools, including EDR, XDR, IDS/IPS, and malware defense platforms
- Hands-on threat hunting experience
- In-depth knowledge of adversary tactics and techniques, including obfuscation, persistence, privilege escalation, lateral movement, and defense evasion
- Strong working knowledge of Windows operating systems, with additional experience in Linux or macOS environments
- Strong ability to analyze Windows event logs and other telemetry data
- Solid understanding of network traffic analysis, TCP/IP, routing, switching, and protocols
- Experience mentoring, coaching, or reviewing other analysts
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity or related field, or equivalent practical experience
- Business-level Japanese (JLPT N2 or above, or native), written and spoken
- Business-level English, written and spoken
- Willingness to participate in shift work including nights, weekends and holidays
- Desirable: MITRE ATT&CK, SIEM platforms, SQL, OSQuery, PowerShell, and advanced cybersecurity certifications such as GCIH, GCFA, GCIA, GREM, OSCP, or CISSP
Benefits:
- Remote-first working model
- Employee-led diversity and inclusion networks
- Annual charity and fundraising initiatives
- Volunteer days
- Global employee sustainability initiatives
- Global fitness and trivia competitions
- Global wellbeing days
- Monthly wellbeing webinars and training
- Recruitment process adjustments to support applicants with disabilities or other needs
















