Senior Incident Response Analyst, MDR

Posted 2 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Incident Response Analyst leading complex cyber investigations for Sophos MDR customers. Directing containment, forensic response, and technical guidance within Sophos’s cybersecurity services.

Responsibilities

  • Support Managed Detection and Response (MDR) customers within the Critical Incident Response Team (CIRT)
  • Lead complex investigations involving advanced adversaries, multi-vector intrusions, or cross-environment compromise
  • Serve as the primary Incident Advisor or delegated Commander for high-severity engagements
  • Direct and coordinate investigative, forensic, and containment activities across multiple analysts
  • Define engagement strategy, investigative priorities, and containment approaches based on risk and impact
  • Validate and synthesize technical findings into clear, actionable guidance for customers and internal stakeholders
  • Provide technical mentorship and oversight to IR and SOC analysts
  • Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to validate detections and close visibility gaps
  • Lead or contribute to post-incident reviews, driving improvements to playbooks, tools, and response workflows
  • Maintain accurate time and activity tracking to support operational visibility and capacity planning

Requirements

  • 5+ years of experience in incident response, MDR, or cyber security investigations, including leadership of complex incidents
  • Advanced expertise in endpoint and network forensics, log analysis, and adversary tradecraft
  • Strong understanding of enterprise network architecture and IT infrastructure
  • Proven ability to lead investigations, validate findings, and design effective containment strategies
  • Experience communicating technical findings to customers, including senior and executive stakeholders
  • Demonstrated mentorship and leadership across incident response teams
  • Ability to operate effectively under high-pressure, time-sensitive conditions
  • Willingness to work some weekends and holidays as part of a rotation
  • Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent) — desired
  • Experience acting as Incident Advisor or Commander during critical engagements — desired
  • Publications, presentations, or recognized contributions within the cybersecurity field — desired
  • Experience influencing detection strategy, tooling improvements, or service design — desired
  • Strong customer-facing presence with experience briefing executives during incidents — desired
  • Legal authorization to work in Canada without requiring employer sponsorship

Benefits

  • Bonus eligibility
  • Comprehensive benefits package
  • Remote-first working model
  • Employee-led diversity and inclusion networks
  • Annual charity and fundraising initiatives
  • Volunteer days
  • Global employee sustainability initiatives
  • Global fitness and trivia competitions
  • Global wellbeing days
  • Monthly wellbeing webinars and training
  • Equality of opportunity and recruitment adjustments where needed

Job type

Full Time

Experience level

Senior

Salary

CA$131,000 - CA$219,000 per year

Degree requirement

No Education Requirement

Tech skills

Cyber Security

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.