Principal Incident Response Engineer

Posted last week

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Principal Incident Response Consultant serving as a trusted advisor for organizations on cybersecurity. Leading proactive engagements and incident responses leveraging comprehensive cybersecurity expertise.

Responsibilities

  • Conduct comprehensive reviews of incident response plans, identifying gaps and developing tailored strategies to strengthen organizational preparedness.
  • Design and deliver customized incident response playbooks to address specific threats and operational needs.
  • Facilitate training sessions on incident response fundamentals to build customer capabilities.
  • Lead workshops, tabletop exercises, drills, and functional simulations to evaluate and improve readiness.
  • Provide strategic guidance to customers on integrating readiness into broader security programs.
  • Serve as a subject matter expert in digital forensics and incident response (DFIR).
  • Lead large-scale, complex investigations involving host, network, and cloud artifacts to determine the nature, scope, and root cause of cyber incidents.
  • Guide containment, remediation, and recovery efforts to secure environments post-incident.
  • Maintain a professional, calming, and authoritative presence during high-pressure incidents.
  • Brief senior leadership and technical teams on findings, risks, and recommendations.

Requirements

  • Comprehensive experience in both readiness and incident response.
  • Strong analytical and problem-solving skills.
  • Ability to lead and mentor cross-functional teams.
  • Excellent communication skills, including executive briefings.
  • Proven ability to manage high-stakes engagements.
  • Experience with forensic tools and techniques (e.g., EDR, log analysis, malware analysis).
  • Familiarity with enterprise environments including Windows, Linux, Azure, AWS, and M365.
  • Strong understanding of attacker Tactics, Techniques, and Procedures (TTPs) and modern detection and response strategies.
  • Willingness to travel up to 20%, including on short notice, to support on-site customer engagements.
  • 12–15 years of experience in cybersecurity or related fields, with a focus on incident response and readiness.
  • Demonstrated ability to lead high-profile incidents and readiness initiatives.

Benefits

  • Sophos operates a remote-first working model, making remote work the primary option for most employees.
  • Employee-led diversity and inclusion networks that build community and provide education and advocacy.
  • Annual charity and fundraising initiatives and volunteer days for employees to support local communities.
  • Global employee sustainability initiatives to reduce our environmental footprint.
  • Global fitness and trivia competitions to keep our bodies and minds sharp.
  • Global wellbeing days for employees to relax and recharge.
  • Monthly wellbeing webinars and training to support employee health and wellbeing.

Job type

Full Time

Experience level

Lead

Salary

CA$161,000 - CA$268,000 per year

Degree requirement

Bachelor's Degree

Tech skills

AWSAzureCloudCyber SecurityLinux

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.