Sophos is seeking a highly skilled Senior Incident Response Analyst to support Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT).
As a Senior Incident Response Analyst 2, you will lead complex and high-impact incident response engagements, operating across Responder, Advisor, and Commander roles as required. You are trusted to provide advanced technical leadership, shape investigative strategy, guide containment decisions, and ensure high-quality customer outcomes during critical security incidents.
What You Will Do
- Lead complex investigations involving advanced adversaries, multi-vector intrusions, or cross-environment compromise
- Serve as the primary Incident Advisor or delegated Commander for high-severity engagements
- Direct and coordinate investigative, forensic, and containment activities across multiple analysts
- Define engagement strategy, investigative priorities, and containment approaches based on risk and impact
- Validate and synthesize technical findings into clear, actionable guidance for customers and internal stakeholders
- Provide technical mentorship and oversight to IR and SOC analysts
- Collaborate closely with SOC, Threat Intelligence, and Detection Engineering teams to validate detections and close visibility gaps
- Lead or contribute to post-incident reviews, driving improvements to playbooks, tools, and response workflows
- Maintain accurate time and activity tracking to support operational visibility and capacity planning
What You Will Bring
- 5+ years of experience in incident response, MDR, or cyber security investigations, including leadership of complex incidents
- Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft
- Strong understanding of enterprise network architecture and IT infrastructure
- Proven ability to lead investigations, validate findings, and design effective containment strategies
- Experience communicating technical findings to customers, including senior and executive stakeholders
- Demonstrated mentorship and leadership across incident response teams
- Ability to operate effectively under high-pressure, time-sensitive conditions
- Willingness to work some weekends and holidays as part of a rotation
- Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent)
- Experience acting as Incident Advisor or Commander during critical engagements
- Publications, presentations, or recognized contributions within the cybersecurity field
- Experience influencing detection strategy, tooling improvements, or service design
- Strong customer-facing presence with experience briefing executives during incidents
Essential:
Desired:
Skills Required
- 5+ years of experience in incident response, managed detection and response, or cybersecurity investigations, including leadership of complex incidents
- Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft
- Strong understanding of enterprise network architecture and IT infrastructure
- Ability to lead investigations, validate findings, and design effective containment strategies
- Experience communicating technical findings to customers, including senior and executive stakeholders
- Demonstrated mentorship and leadership across incident response teams
- Ability to operate effectively under high-pressure, time-sensitive conditions
- Willingness to work some weekends and holidays as part of a rotation
- Advanced incident response or forensic certification such as GCFA, GCED, GCIH, OSCP, or equivalent
- Experience acting as Incident Advisor or Commander during critical engagements
- Publications, presentations, or recognized contributions within the cybersecurity field
- Experience influencing detection strategy, tooling improvements, or service design
- Customer-facing experience briefing executives during incidents
Sophos Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sophos and has not been reviewed or approved by Sophos.
-
Leave & Time Off Breadth — Time away is positioned as broad, with company-wide wellness days plus dedicated learning days and paid volunteer time.
-
Parental & Family Support — Family-related leave appears more comprehensive than baseline offerings, including paid parental leave, caregiver leave, and extended bereavement leave.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is emphasized through always-available assistance resources and a Calm subscription, suggesting a lifestyle-oriented benefits approach.
Sophos Insights
What We Do
Cybersecurity Evolved. As a worldwide leader in next-generation cybersecurity, Sophos protects nearly 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats. Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more.









