Principal Incident Response Consultant serving as a trusted advisor for organizations on cybersecurity. Leading proactive engagements and incident responses leveraging comprehensive cybersecurity expertise.
Responsibilities
Conduct comprehensive reviews of incident response plans, identifying gaps and developing tailored strategies to strengthen organizational preparedness.
Design and deliver customized incident response playbooks to address specific threats and operational needs.
Facilitate training sessions on incident response fundamentals to build customer capabilities.
Lead workshops, tabletop exercises, drills, and functional simulations to evaluate and improve readiness.
Provide strategic guidance to customers on integrating readiness into broader security programs.
Serve as a subject matter expert in digital forensics and incident response (DFIR).
Lead large-scale, complex investigations involving host, network, and cloud artifacts to determine the nature, scope, and root cause of cyber incidents.
Guide containment, remediation, and recovery efforts to secure environments post-incident.
Maintain a professional, calming, and authoritative presence during high-pressure incidents.
Brief senior leadership and technical teams on findings, risks, and recommendations.
Requirements
Comprehensive experience in both readiness and incident response.
Strong analytical and problem-solving skills.
Ability to lead and mentor cross-functional teams.
Excellent communication skills, including executive briefings.
Proven ability to manage high-stakes engagements.
Experience with forensic tools and techniques (e.g., EDR, log analysis, malware analysis).
Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365.
Strong understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection and response strategies.
Willingness to travel up to 20%, including on short notice, to support on-site customer engagements.
12–15 years of experience in cybersecurity or related fields, with a focus on incident response and readiness.
Demonstrated ability to lead high-profile incidents and readiness initiatives.
Benefits
Sophos operates a remote-first working model, making remote work the primary option for most employees.
Employee-led diversity and inclusion networks that build community and provide education and advocacy.
Annual charity and fundraising initiatives and volunteer days for employees to support local communities.
Global employee sustainability initiatives to reduce our environmental footprint.
Global fitness and trivia competitions to keep our bodies and minds sharp.
Global wellbeing days for employees to relax and recharge.
Monthly wellbeing webinars and training to support employee health and wellbeing.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.