Senior Incident Response Analyst, MDR

🔥 0 minutes ago

🇨🇦 Canada – Remote

💵 $131k - $219k / year

⏰ Full Time

🟠 Senior

🚨 Incident Response Analyst

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sophos

Sophos

1001 - 5000 employees

Founded 1985

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

💰 Post-IPO Equity on 2021-08

Consulting • Healthcare • Manufacturing

Sophos is a leading cybersecurity company that specializes in protecting businesses against advanced cyber threats. The company offers a comprehensive suite of security solutions, including endpoint protection, managed detection and response (MDR), network security, and cloud security. With a prevention-first approach, Sophos aims to stop ransomware and other cyber threats before they cause harm. Sophos provides services such as threat research, security training, and operational support to ensure robust defense against cyberattacks. Their solutions cater to various industries including finance, healthcare, government, manufacturing, and retail. The Sophos Central platform delivers centralized security management, integrating seamlessly with existing IT infrastructure to enhance security posture.

📋 Description

• Support Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT) • Lead complex investigations involving advanced adversaries, multi-vector intrusions, or cross-environment compromise • Serve as the primary Incident Advisor or delegated Commander for high-severity engagements • Direct and coordinate investigative, forensic, and containment activities across multiple analysts • Define engagement strategy, investigative priorities, and containment approaches based on risk and impact • Validate and synthesize technical findings into clear, actionable guidance for customers and internal stakeholders • Provide technical mentorship and oversight to IR and SOC analysts • Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to validate detections and close visibility gaps • Lead or contribute to post-incident reviews, driving improvements to playbooks, tools, and response workflows • Maintain accurate time and activity tracking to support operational visibility and capacity planning

🎯 Requirements

• 5+ years of experience in incident response, MDR, or cyber security investigations, including leadership of complex incidents • Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft • Strong understanding of enterprise network architecture and IT infrastructure • Proven ability to lead investigations, validate findings, and design effective containment strategies • Experience communicating technical findings to customers, including senior and executive stakeholders • Demonstrated mentorship and leadership across incident response teams • Ability to operate effectively under high-pressure, time-sensitive conditions • Willingness to work some weekends and holidays as part of a rotation • Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent) — desired • Experience acting as Incident Advisor or Commander during critical engagements — desired • Publications, presentations, or recognized contributions within the cybersecurity field — desired • Experience influencing detection strategy, tooling improvements, or service design — desired • Strong customer-facing presence with experience briefing executives during incidents — desired • Legal authorization to work in Canada without requiring employer sponsorship

🏖️ Benefits

• Bonus eligibility • Comprehensive benefits package • Remote-first working model • Employee-led diversity and inclusion networks • Annual charity and fundraising initiatives • Volunteer days • Global employee sustainability initiatives • Global fitness and trivia competitions • Global wellbeing days • Monthly wellbeing webinars and training • Equality of opportunity and recruitment adjustments where needed

Apply Now