As a Principal Incident Response & Readiness Consultant, you will serve as a trusted advisor, leading both proactive and emergency engagements with enterprise customers. Leveraging your comprehensive expertise in cybersecurity, you will help organizations prepare for and respond to cyber incidents, combining strategic readiness consulting with direct guidance through complex cyber incidents.
What You Will Do
- Readiness
- Conduct comprehensive reviews of incident response plans, identifying gaps and developing tailored strategies to strengthen organizational preparedness.
- Design and deliver customized incident response playbooks to address specific threats and operational needs.
- Facilitate training sessions on incident response fundamentals to build customer capabilities.
- Lead workshops, tabletop exercises, drills, and functional simulations to evaluate and improve readiness.
- Provide strategic guidance to customers on integrating readiness into broader security programs.
- Contribute to the development of readiness methodologies and internal knowledge sharing.
- Incident Response
- Serve as a subject matter expert in digital forensics and incident response (DFIR).
- Lead large-scale, complex investigations involving host, network, and cloud artifacts to determine the nature, scope, and root cause of cyber incidents.
- Collaborate and coordinate with cross-functional incident response teams.
- Guide containment, remediation, and recovery efforts to secure environments post-incident.
- Maintain a professional, calming, and authoritative presence during high-pressure incidents.
- Brief senior leadership and technical teams on findings, risks, and recommendations.
- Support the development of incident response methodologies and contribute to internal capability building.
- Participate in a 24x7 emergency response rotation which includes weekends.
What You Will Bring
- Comprehensive experience in both readiness and incident response.
- Strong analytical and problem-solving skills.
- Ability to lead and mentor cross-functional teams.
- Excellent communication skills, including executive briefings.
- Proven ability to manage high-stakes engagements.
- Experience with forensic tools and techniques (e.g., EDR, log analysis, malware analysis).
- Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365.
- Strong understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection and response strategies.
- Willingness to travel up to 20%, including on short notice, to support on-site customer engagements.
- 12–15 years of experience in cybersecurity or related fields, with a focus on incident response and readiness.
- Demonstrated ability to lead high-profile incidents and readiness initiatives.
- Relevant certifications (e.g., GIAC, CISSP, CISM, or similar) are a plus but not required; proven impact and expertise are primary qualifiers.
Education and Experience
Skills Required
- 12-15 years of experience in cybersecurity or related fields
- Comprehensive experience in both readiness and incident response
- Experience with forensic tools and techniques
- Proven ability to manage high-stakes engagements
- Excellent communication skills, including executive briefings
- Strong analytical and problem-solving skills
- Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365
Sophos Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sophos and has not been reviewed or approved by Sophos.
-
Leave & Time Off Breadth — Time away is positioned as broad, with company-wide wellness days plus dedicated learning days and paid volunteer time.
-
Parental & Family Support — Family-related leave appears more comprehensive than baseline offerings, including paid parental leave, caregiver leave, and extended bereavement leave.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is emphasized through always-available assistance resources and a Calm subscription, suggesting a lifestyle-oriented benefits approach.
Sophos Insights
What We Do
Cybersecurity Evolved. As a worldwide leader in next-generation cybersecurity, Sophos protects nearly 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats. Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more.


.png)





