Team Lead – Threat Analyst

Posted 3hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Operations Manager overseeing threat analysts and incident response. Supporting Sophos’s global cybersecurity, managed detection, and response operations.

Responsibilities:

  • Maintain supervision over operational tasks and provide day-to-day oversight for threat analysts
  • Oversee analysts in their investigation and response
  • Determine possible root cause and resolution when security incidents arise
  • Communicate information effectively to stakeholders at all levels
  • Apply network and host-based intrusion analysis, incident response processes and procedures, digital forensics, and malware-handling expertise
  • Act as a lead throughout incident scenarios and provide cybersecurity incident response subject matter expertise
  • Execute incident handling procedures and directly respond to cybersecurity incidents
  • Maintain current knowledge of attacker tools, tactics, and procedures
  • Produce indicators of compromise (IOCs) for active and future investigations
  • Assess cyber threat intelligence and open source intelligence and operationalize that information
  • Handle sophisticated malware and dynamic cyber threat actors
  • Identify current and emerging threats and apply related research
  • Manage the operational effectiveness of the Security Operations Center and its personnel
  • Ensure the strategic and operational mission of the MDR team is fulfilled

Requirements:

  • 5+ years of experience within a cybersecurity environment
  • Bachelor's in information technology, Computer Science, or a related field; or relevant, commensurate work experience
  • Experience in a security operations center or similar environment
  • Experience identifying indications of compromise or attack and responding to incidents
  • Endpoint and network security experience, including IDS, IPS, EDR, ATP, malware defenses, and monitoring
  • Knowledge of common adversary tactics and techniques, including obfuscation, persistence, and defense evasion
  • Working knowledge of incident response procedures
  • Experience administering and supporting Windows OS workstations and servers and either Apple or Linux-based operating systems
  • Fundamental understanding of network traffic analysis, including TCP/IP, routing, switching, and protocols
  • Threat hunting experience preferred
  • Knowledge of the Mitre ATT&CK framework preferred
  • Experience with SQL query construction preferred
  • Experience with OSQuery is a plus
  • Leadership experience preferred

Benefits:

  • Remote-first working model, with remote work as the primary option for most employees
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days for employees
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training
  • Recruitment and selection process adjustments for accessibility when needed