Incident Response Engineer – Level 2

🔥 8 minutes ago

🇬🇧 United Kingdom – Remote

⏰ Full Time

🟢 Junior

🟡 Mid-level

👮‍♂️ Cybersecurity / Security Engineer

🚫👨‍🎓 No degree required

🇬🇧 UK Skilled Worker Visa Sponsor

infoinfo

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sophos

Sophos

1001 - 5000 employees

Founded 1985

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

💰 Post-IPO Equity on 2021-08

Consulting • Healthcare • Manufacturing

Sophos is a leading cybersecurity company that specializes in protecting businesses against advanced cyber threats. The company offers a comprehensive suite of security solutions, including endpoint protection, managed detection and response (MDR), network security, and cloud security. With a prevention-first approach, Sophos aims to stop ransomware and other cyber threats before they cause harm. Sophos provides services such as threat research, security training, and operational support to ensure robust defense against cyberattacks. Their solutions cater to various industries including finance, healthcare, government, manufacturing, and retail. The Sophos Central platform delivers centralized security management, integrating seamlessly with existing IT infrastructure to enhance security posture.

📋 Description

• Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry • Execute containment and response actions to neutralize active threats as directed by Incident Advisors or Senior Analysts • Validate indicators of compromise and correlate alerts, artifacts, and telemetry to determine scope and root cause • Maintain clear and accurate engagement documentation, including trailheads, timelines, and playbooks • Provide guidance and mentorship to junior IR and SOC analysts • Prepare technical findings and summaries for customer updates and post-incident reports • Identify and communicate detection or response gaps observed during investigations • Participate in shift handovers, debriefs, and post-incident reviews • Maintain accurate time and activity tracking • Support Managed Detection and Response customers within Sophos's Critical Incident Response Team

🎯 Requirements

• 2+ years of experience in incident response, MDR, SOC, or security operations roles • Solid technical understanding of endpoint forensics, log analysis, and common attack techniques • Experience investigating malware, credential theft, ransomware, or similar threats • Ability to correlate alerts and telemetry to determine incident scope and root cause • Strong written and verbal communication skills for documenting findings and contributing to customer updates • Experience mentoring or guiding junior analysts • Ability to work effectively in high-pressure, time-sensitive incident environments • Willingness to work some weekends and holidays as part of a rotation • Hands-on experience with EDR, SIEM, and forensic collection tools • Familiarity with OSQuery, SQL, or KQL • Knowledge of MITRE ATT&CK and incident response frameworks • Industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent • Experience contributing to playbooks, detection tuning, or service improvement initiatives • Legal authorization to work in the United Kingdom without employer sponsorship

🏖️ Benefits

• Remote-first working model, with remote work as the primary option for most employees • Employee-led diversity and inclusion networks • Annual charity and fundraising initiatives • Volunteer days • Global employee sustainability initiatives • Global fitness and trivia competitions • Global wellbeing days • Monthly wellbeing webinars and training • Recruitment and selection process adjustments available for applicants who need them

Apply Now

Similar Jobs

🕒 September 8

AISLE™

11 - 50

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Forward Deployed Engineer deploying AISLE’s AI-powered autonomous vulnerability-remediation platform. Integrating security systems and code across UK and EU government, defense, and enterprise environments.

🕒 September 3

Fika

11 - 50

🏥 Healthcare

💼 Consulting

🎲 Gambling

IT Security Specialist protecting Fika’s rural infrastructure nonprofit systems from cyber threats. Securing networks, cloud environments, endpoints, and compliance operations across global program offices.

🕒 August 27

Telefónica Tech

1001 - 5000

🏥 Healthcare

🛡️ Insurance

🏭 Manufacturing

Cyber Security Manager overseeing managed SOC, SIEM, MDR and incident response services for Telefónica Tech enterprise customers. Leading governance, customer success and cyber resilience improvements.

🕒 August 25

Immersive Labs

201 - 500

🔒 Cybersecurity

📚 Education

☁️ SaaS

Senior Cyber Security Engineer creating red-team labs, ranges and AI penetration-testing content. Strengthening Immersive Labs’ global cyber resilience platform through realistic attack simulations.

🕒 August 25

Ping Identity

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

Cyber Security Manager leading incident response, detection engineering, and security operations. Protecting Ping Identity’s cloud identity platform and enterprise systems.

🇬🇧 United Kingdom – Remote

💰 $35M Series F - Ping Identity on 2014-09

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer