Incident Response Analyst

🔥 0 minutes ago

🇦🇺 Australia – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚨 Incident Response Analyst

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sophos

Sophos

1001 - 5000 employees

Founded 1985

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

💰 Post-IPO Equity on 2021-08

Consulting • Healthcare • Manufacturing

Sophos is a leading cybersecurity company that specializes in protecting businesses against advanced cyber threats. The company offers a comprehensive suite of security solutions, including endpoint protection, managed detection and response (MDR), network security, and cloud security. With a prevention-first approach, Sophos aims to stop ransomware and other cyber threats before they cause harm. Sophos provides services such as threat research, security training, and operational support to ensure robust defense against cyberattacks. Their solutions cater to various industries including finance, healthcare, government, manufacturing, and retail. The Sophos Central platform delivers centralized security management, integrating seamlessly with existing IT infrastructure to enhance security posture.

📋 Description

• Lead the investigative stream of active cyber incidents for Managed Detection and Response customers • Perform advanced forensic, analytical, and containment tasks across diverse customer environments • Investigate, contain, and respond to cyber incidents using Sophos technologies • Analyze malware, ransomware, and other common attack types • Maintain accurate and detailed documentation of incident analysis • Recognize and codify attacker tools, tactics, and procedures • Communicate clearly with MDR customers during cyber incidents • Collaborate with SophosLabs, Detection Engineering, and Threat Hunting teams to improve detection logic • Work with MDR Operations teams on response, remediation guidance, and customer service • Create technical incident reports for MDR customers and MSPs • Support Advisors by validating findings, shaping investigative direction, and preparing technical context for customer communication • Operate with moderate autonomy while ensuring technical accuracy, investigative consistency, and high-quality documentation

🎯 Requirements

• 3+ years of experience conducting cyber security investigations in a methodical manner and investigating threats • Knowledge of incident response toolsets, methodologies, and techniques • Experience creating technical documentation and technical reports • Ability to work under high-pressure situations, when response time matters, to disrupt adversary activity • Network and endpoint investigation experience across macOS, Linux, and Windows • Experience with IDS, IPS, EDR, and basic malware analysis • Basic understanding of at least one of: OSQuery, SQL, and KQL • Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks • Ability to work some weekends and holidays • Experience with Windows and Linux command and script interpreters • Cyber security certifications such as GCIH, CompTIA Security+, or eJPT (desired) • Experience with incident response investigations, handling malware, and performing response actions to contain and/or neutralize threats (desired) • Experience calling customers and providing excellent customer service (desired) • Legal authorization to work in Australia without employer sponsorship

🏖️ Benefits

• Sophos operates a remote-first working model, making remote work the primary option for most employees • Employee-led diversity and inclusion networks • Annual charity and fundraising initiatives • Volunteer days for employees to support local communities • Global employee sustainability initiatives • Global fitness and trivia competitions • Global wellbeing days • Monthly wellbeing webinars and training to support employee health and wellbeing

Apply Now